IgnitionServer Locked Channel Protected Operator Lockout Vulnerability
BID:13656
Info
IgnitionServer Locked Channel Protected Operator Lockout Vulnerability
| Bugtraq ID: | 13656 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2005 12:00AM |
| Updated: | May 17 2005 12:00AM |
| Credit: | Discovered by WebdesignX007 <[email protected]>. |
| Vulnerable: |
The Ignition Project ignitionServer 0.3.6 The Ignition Project ignitionServer 0.3.4 a beta4 The Ignition Project ignitionServer 0.3.3 beta3 The Ignition Project ignitionServer 0.3.2 beta2 The Ignition Project ignitionServer 0.3.1 -P1 The Ignition Project ignitionServer 0.3.1 beta1 The Ignition Project ignitionServer 0.3.1 The Ignition Project ignitionServer 0.3 .0 |
| Not Vulnerable: |
The Ignition Project ignitionServer 0.3.6 -P1 |
Discussion
IgnitionServer Locked Channel Protected Operator Lockout Vulnerability
ignitionServer is prone to an issue that can allow a user to lock a protected operator out of an IRC channel. This issue occurs because a validation check that should allow the protected operator to access the locked channel was not included in the application.
This issue was addressed in ignitionServer 0.3.6-P1.
ignitionServer is prone to an issue that can allow a user to lock a protected operator out of an IRC channel. This issue occurs because a validation check that should allow the protected operator to access the locked channel was not included in the application.
This issue was addressed in ignitionServer 0.3.6-P1.
Exploit / POC
IgnitionServer Locked Channel Protected Operator Lockout Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
IgnitionServer Locked Channel Protected Operator Lockout Vulnerability
Solution:
A fix is available.
The Ignition Project ignitionServer 0.3 .0
The Ignition Project ignitionServer 0.3.1
The Ignition Project ignitionServer 0.3.1 beta1
The Ignition Project ignitionServer 0.3.1 -P1
The Ignition Project ignitionServer 0.3.2 beta2
The Ignition Project ignitionServer 0.3.3 beta3
The Ignition Project ignitionServer 0.3.4 a beta4
The Ignition Project ignitionServer 0.3.6
Solution:
A fix is available.
The Ignition Project ignitionServer 0.3 .0
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.1
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.1 beta1
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.1 -P1
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.2 beta2
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.3 beta3
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.4 a beta4
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.6
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
References
IgnitionServer Locked Channel Protected Operator Lockout Vulnerability
References:
References:
- Security Bulletin: Protected IRC operators cannot join channels with keys (The Ignition Project)
- The Ignition Project Homepage (The Ignition Project)