BNC getnickuserhost IRC Server Response Buffer Overflow Vulnerability
BID:11647
Info
BNC getnickuserhost IRC Server Response Buffer Overflow Vulnerability
| Bugtraq ID: | 11647 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1052 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery is credited to Leon Juranic of LSS Security Team. |
| Vulnerable: |
Gentoo Linux Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha BNC BNC 2.8.9 BNC BNC 2.8.8 BNC BNC 2.6.4 BNC BNC 2.6.2 BNC BNC 2.6 BNC BNC 2.4.8 BNC BNC 2.4.6 BNC BNC 2.2.4 |
| Not Vulnerable: |
BNC BNC 2.9.1 BNC BNC 2.9 .0 |
Discussion
BNC getnickuserhost IRC Server Response Buffer Overflow Vulnerability
A remotely exploitable stack-based buffer overflow has been reported in BNC. This issue may be triggered when a malformed IRC (Internet Relay Chat) server response is handled by the proxy.
If successfully exploited, this would allow execution of arbitrary code in the context of the proxy.
A remotely exploitable stack-based buffer overflow has been reported in BNC. This issue may be triggered when a malformed IRC (Internet Relay Chat) server response is handled by the proxy.
If successfully exploited, this would allow execution of arbitrary code in the context of the proxy.
Exploit / POC
BNC getnickuserhost IRC Server Response Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BNC getnickuserhost IRC Server Response Buffer Overflow Vulnerability
Solution:
This issue is addressed in version 2.9.0 and later.
Debian Linux has released an advisory (DSA 595-1) and fixes dealing with this issue. Please see referenced advisory for further information.
Gentoo Linux has released an advisory (GLSA 200411-24) dealing with this issue. Gentoo has advised that all BNC users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-irc/bnc-2.9.1"
For more information please see the referenced Gentoo Linux advisory.
BNC BNC 2.2.4
BNC BNC 2.4.6
BNC BNC 2.4.8
BNC BNC 2.6
BNC BNC 2.6.2
BNC BNC 2.6.4
BNC BNC 2.8.8
BNC BNC 2.8.9
Solution:
This issue is addressed in version 2.9.0 and later.
Debian Linux has released an advisory (DSA 595-1) and fixes dealing with this issue. Please see referenced advisory for further information.
Gentoo Linux has released an advisory (GLSA 200411-24) dealing with this issue. Gentoo has advised that all BNC users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-irc/bnc-2.9.1"
For more information please see the referenced Gentoo Linux advisory.
BNC BNC 2.2.4
-
BNC bnc2.9.1.tar.gz
http://www.gotbnc.com/files/bnc2.9.1.tar.gz
BNC BNC 2.4.6
-
BNC bnc2.9.1.tar.gz
http://www.gotbnc.com/files/bnc2.9.1.tar.gz
BNC BNC 2.4.8
-
BNC bnc2.9.1.tar.gz
http://www.gotbnc.com/files/bnc2.9.1.tar.gz
BNC BNC 2.6
-
BNC bnc2.9.1.tar.gz
http://www.gotbnc.com/files/bnc2.9.1.tar.gz
BNC BNC 2.6.2
-
BNC bnc2.9.1.tar.gz
http://www.gotbnc.com/files/bnc2.9.1.tar.gz
BNC BNC 2.6.4
-
Debian bnc_2.6.4-3.3_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_alpha .deb -
Debian bnc_2.6.4-3.3_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_arm.d eb -
Debian bnc_2.6.4-3.3_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_hppa. deb -
Debian bnc_2.6.4-3.3_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_i386. deb -
Debian bnc_2.6.4-3.3_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_ia64. deb -
Debian bnc_2.6.4-3.3_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_m68k. deb -
Debian bnc_2.6.4-3.3_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_mips. deb -
Debian bnc_2.6.4-3.3_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_mipse l.deb -
Debian bnc_2.6.4-3.3_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_power pc.deb -
Debian bnc_2.6.4-3.3_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_s390. deb -
Debian bnc_2.6.4-3.3_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bnc/bnc_2.6.4-3.3_sparc .deb
BNC BNC 2.8.8
-
BNC bnc2.9.1.tar.gz
http://www.gotbnc.com/files/bnc2.9.1.tar.gz
BNC BNC 2.8.9
-
BNC bnc2.9.1.tar.gz
http://www.gotbnc.com/files/bnc2.9.1.tar.gz
References
BNC getnickuserhost IRC Server Response Buffer Overflow Vulnerability
References:
References:
- BNC Home Page (BNC)
- BNC 2.8.9 remote buffer overflow (LSS Security
)