BitchX BX_Do_Hook Remote Denial of Service Vulnerability
BID:18634
Info
BitchX BX_Do_Hook Remote Denial of Service Vulnerability
| Bugtraq ID: | 18634 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2006 12:00AM |
| Updated: | Jun 26 2006 04:05PM |
| Credit: | Federico L. Bossi Bonin <[email protected]> discovered this issue. |
| Vulnerable: |
BitchX IRC Client 1.1 -final |
| Not Vulnerable: | |
Discussion
BitchX BX_Do_Hook Remote Denial of Service Vulnerability
BitchX is prone to a remote denial-of-service vulnerability because it fails to properly handle excessive data from malicious IRC servers.
This issue allows remote attackers to crash affected IRC clients, denying service to legitimate users. To exploit this issue, attackers must coerce users of affected clients to connect to a malicious server.
BitchX version 1.1-final is vulnerable to this issue; previous versions may also be affected.
BitchX is prone to a remote denial-of-service vulnerability because it fails to properly handle excessive data from malicious IRC servers.
This issue allows remote attackers to crash affected IRC clients, denying service to legitimate users. To exploit this issue, attackers must coerce users of affected clients to connect to a malicious server.
BitchX version 1.1-final is vulnerable to this issue; previous versions may also be affected.
Exploit / POC
BitchX BX_Do_Hook Remote Denial of Service Vulnerability
The following exploit code is available to demonstrate this issue:
The following exploit code is available to demonstrate this issue:
Solution / Fix
BitchX BX_Do_Hook Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].