The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by sending a client message before providing the nickname, which triggers a null pointer dereference. This vulnerability is addressed in the following product release:
DConnect, DConnect Daemon, 0.7.1
Publication date: Tue, 15 Aug 2006 04:04:00 +0000