{"id":"DEBIAN-CVE-2009-4016","details":"Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.","modified":"2026-09-22T16:47:32.586729109Z","published":"2010-02-04T20:15:23.750Z","upstream":["CVE-2009-4016"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2009-4016"}],"affected":[{"package":{"name":"ircd-hybrid","ecosystem":"Debian:12","purl":"pkg:deb/debian/ircd-hybrid?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:7.2.2.dfsg.2-6.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-4016.json"}},{"package":{"name":"ircd-hybrid","ecosystem":"Debian:13","purl":"pkg:deb/debian/ircd-hybrid?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:7.2.2.dfsg.2-6.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-4016.json"}}],"schema_version":"1.9.0"}