SILC Toolkit and SILC Client NICK_CHANGE Remote Buffer Overflow Vulnerability
BID:24795
Info
SILC Toolkit and SILC Client NICK_CHANGE Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 24795 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3728 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SILC Toolkit 1.1.1 SILC Toolkit 1.1 SILC Client 1.1.1 |
| Not Vulnerable: |
SILC Toolkit 1.1.2 SILC Client 1.1.2 |
Discussion
SILC Toolkit and SILC Client NICK_CHANGE Remote Buffer Overflow Vulnerability
SILC Toolkit and SILC Client are prone to a remote buffer-overflow vulnerability because they fail to perform adequate boundary checks on user-supplied input before copying it into an insufficiently sized memory buffer.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to SILC Toolkit and SILC Client 1.1.2 are vulnerable to this issue.
SILC Toolkit and SILC Client are prone to a remote buffer-overflow vulnerability because they fail to perform adequate boundary checks on user-supplied input before copying it into an insufficiently sized memory buffer.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to SILC Toolkit and SILC Client 1.1.2 are vulnerable to this issue.
Exploit / POC
SILC Toolkit and SILC Client NICK_CHANGE Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SILC Toolkit and SILC Client NICK_CHANGE Remote Buffer Overflow Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
SILC Toolkit 1.1
SILC Toolkit 1.1.1
SILC Client 1.1.1
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
SILC Toolkit 1.1
-
SILC SILC Toolkit 1.1.2
http://silcnet.org/software/download/toolkit/
SILC Toolkit 1.1.1
-
SILC SILC Toolkit 1.1.2
http://silcnet.org/software/download/toolkit/
SILC Client 1.1.1
-
SILC SILC Client 1.1.2
http://silcnet.org/software/download/client/ -
SILC SILC Toolkit 1.1.2
http://silcnet.org/software/download/toolkit/
References
SILC Toolkit and SILC Client NICK_CHANGE Remote Buffer Overflow Vulnerability
References:
References:
- SILC Webpage (SILC)
- SILC Changelog (SILC)