Candidate: CVE-2014-9773 PublicDate: 2016-06-13 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9773 https://github.com/atheme/atheme/issues/397 http://www.openwall.com/lists/oss-security/2016/05/02/2 https://github.com/atheme/atheme/commit/5c734f28068cf47b9b450af4dcf37195734b15be (introduced in) Description: modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks. Ubuntu-Description: Notes: sbeattie> possibly only affects 7.x. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_atheme-services: upstream: https://github.com/atheme/atheme/commit/c597156adc60a45b5f827793cd420945f47bc03b upstream_atheme-services: released (7.0.7-2) precise_atheme-services: DNE precise/esm_atheme-services: DNE trusty_atheme-services: ignored (reached end-of-life) trusty/esm_atheme-services: DNE (trusty was needs-triage) vivid/stable-phone-overlay_atheme-services: DNE vivid/ubuntu-core_atheme-services: DNE wily_atheme-services: ignored (reached end-of-life) xenial_atheme-services: not-affected (code not present) yakkety_atheme-services: ignored (reached end-of-life) zesty_atheme-services: ignored (reached end-of-life) artful_atheme-services: ignored (reached end-of-life) bionic_atheme-services: not-affected (7.0.7-2) cosmic_atheme-services: not-affected (7.0.7-2) disco_atheme-services: not-affected (7.0.7-2) devel_atheme-services: not-affected (7.0.7-2)