BitchX Hook.C Remote Buffer Overflow Vulnerability
BID:24579
Info
BitchX Hook.C Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 24579 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3360 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | clarity is credited with the discovery of this vulnerability. |
| Vulnerable: |
Slackware Linux -current BitchX IRC Client 1.1 -final |
| Not Vulnerable: | |
Discussion
BitchX Hook.C Remote Buffer Overflow Vulnerability
BitchX is prone to a remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects BitchX 1.1-final; other versions may also be affected.
BitchX is prone to a remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects BitchX 1.1-final; other versions may also be affected.
Exploit / POC
BitchX Hook.C Remote Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
BitchX Hook.C Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.