TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnerabilities
BID:27660
Info
TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnerabilities
| Bugtraq ID: | 27660 |
| Class: | Unknown |
| CVE: |
CVE-2008-0671 CVE-2008-0672 CVE-2008-0673 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2008 12:00AM |
| Updated: | Nov 21 2011 06:45PM |
| Credit: | Luigi Auriemma is credited with discovering these vulnerabilities. |
| Vulnerable: |
TinTin++ WinTin++ 1.97.9 TinTin++ TinTin++ 1.97.9 Gentoo Linux |
| Not Vulnerable: | |
Discussion
TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnerabilities
TinTin++ and WinTin++ are prone to multiple security vulnerabilities affecting the application's '#chat' functionality. These issues include a buffer-overflow vulnerability, a denial-of-service vulnerability, and a file-overwrite vulnerability.
Attackers can exploit these issues to execute arbitrary code, cause denial-of-service conditions, or overwrite files with arbitrary content.
These issues affect TinTin++ and WinTin++ 1.97.9; other versions may also be affected.
TinTin++ and WinTin++ are prone to multiple security vulnerabilities affecting the application's '#chat' functionality. These issues include a buffer-overflow vulnerability, a denial-of-service vulnerability, and a file-overwrite vulnerability.
Attackers can exploit these issues to execute arbitrary code, cause denial-of-service conditions, or overwrite files with arbitrary content.
These issues affect TinTin++ and WinTin++ 1.97.9; other versions may also be affected.
Exploit / POC
TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnerabilities
Attackers can exploit these issues with readily available networking tools.
The following proof-of-concept exploit code is available:
Attackers can exploit these issues with readily available networking tools.
The following proof-of-concept exploit code is available:
Solution / Fix
TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnerabilities
References:
References:
- TinTin++ Homepage (TinTin++)
- Chat vulnerabilities in TinTin++ 1.97.9 (Luigi Auriemma
)