{"id":"CVE-2003-0328","details":"EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.","modified":"2026-04-10T03:36:08.201681Z","published":"2003-06-09T04:00:00Z","references":[{"type":"ADVISORY","url":"ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1"},{"type":"ADVISORY","url":"http://www.debian.org/security/2003/dsa-306"},{"type":"ADVISORY","url":"http://www.debian.org/security/2003/dsa-399"},{"type":"FIX","url":"ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1"},{"type":"WEB","url":"http://www.redhat.com/support/errata/RHSA-2003-342.html"}],"schema_version":"1.7.5"}