snircd And ircu 'set_user_mode' Remote Denial of Service Vulnerability
BID:28413
Info
snircd And ircu 'set_user_mode' Remote Denial of Service Vulnerability
| Bugtraq ID: | 28413 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1501 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Chris Porter |
| Vulnerable: |
QuakeNet snircd 1.3.4 ircu ircu 2.10.12.12 |
| Not Vulnerable: | |
Discussion
snircd And ircu 'set_user_mode' Remote Denial of Service Vulnerability
The 'snircd' and 'ircd' daemons are prone to a remote denial-of-service vulnerability because the application fails to properly sanitize user-supplied input.
Successfully exploiting this issue allows remote attackers to crash the application, denying service to legitimate users.
This issue affects versions up to and including 'snircd' 1.3.4 and 'ircu' 2.10.12.12.
The 'snircd' and 'ircd' daemons are prone to a remote denial-of-service vulnerability because the application fails to properly sanitize user-supplied input.
Successfully exploiting this issue allows remote attackers to crash the application, denying service to legitimate users.
This issue affects versions up to and including 'snircd' 1.3.4 and 'ircu' 2.10.12.12.
Exploit / POC
snircd And ircu 'set_user_mode' Remote Denial of Service Vulnerability
The following example command is sufficient to trigger this issue:
/mode nickname i i i i i i i i i i i i i i i r r r r s
The following example command is sufficient to trigger this issue:
/mode nickname i i i i i i i i i i i i i i i r r r r s
Solution / Fix
snircd And ircu 'set_user_mode' Remote Denial of Service Vulnerability
Solution:
The vendor has committed a fix to the 'snircd' mercurial repository. Please see the references for more information.
Solution:
The vendor has committed a fix to the 'snircd' mercurial repository. Please see the references for more information.
References
snircd And ircu 'set_user_mode' Remote Denial of Service Vulnerability
References:
References:
- ircu Homepage (ircu)
- snircd changeset 147: Apply remote crash exploit fix to public repo (QuakeNet)
- snircd Homepage (QuakeNet)
- ircu/snircd remote crash vulnerability (Chris Porter
)