XChat Remote Denial of Service Vulnerability
BID:19398
CVE-2006-4455 |Info
XChat Remote Denial of Service Vulnerability
| Bugtraq ID: | 19398 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2006 12:00AM |
| Updated: | Aug 11 2006 11:35PM |
| Credit: | ratboy discovered this issue. |
| Vulnerable: |
X-Chat X-Chat 2.6.7 |
| Not Vulnerable: | |
Discussion
XChat Remote Denial of Service Vulnerability
XChat is prone to a remote denial-of-service vulnerability because it fails to properly handle unexpected data from malicious IRC users.
This issue allows remote attackers to crash affected IRC clients, denying service to legitimate users. To exploit this issue, attackers send malformed data to unsuspecting users.
XChat version 2.6.7 for Windows is vulnerable to this issue; other versions and platforms may also be affected.
NOTE: The vendor refutes this issue, stating that the exploit has no affect on XChat.
XChat is prone to a remote denial-of-service vulnerability because it fails to properly handle unexpected data from malicious IRC users.
This issue allows remote attackers to crash affected IRC clients, denying service to legitimate users. To exploit this issue, attackers send malformed data to unsuspecting users.
XChat version 2.6.7 for Windows is vulnerable to this issue; other versions and platforms may also be affected.
NOTE: The vendor refutes this issue, stating that the exploit has no affect on XChat.
Exploit / POC
XChat Remote Denial of Service Vulnerability
The following exploit code is available to demonstrate this issue:
The following exploit code is available to demonstrate this issue:
Solution / Fix
XChat Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
NOTE: The vendor refutes this issue, stating that the exploit has no affect on XChat.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
NOTE: The vendor refutes this issue, stating that the exploit has no affect on XChat.