Fujitsu Chocoa "Topic" Buffer Overflow Vulnerability
BID:573
Info
Fujitsu Chocoa "Topic" Buffer Overflow Vulnerability
| Bugtraq ID: | 573 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 1999 12:00AM |
| Updated: | Aug 03 1999 12:00AM |
| Credit: | Posted to the Shadow Penguin Security website August 3, 1999 by UNYUN. |
| Vulnerable: |
Fujitsu Chocoa 1.0 beta7R |
| Not Vulnerable: | |
Discussion
Fujitsu Chocoa "Topic" Buffer Overflow Vulnerability
The Chocoa IRC client has an unchecked buffer in the code that processes channel topics. If the server returns a topic that overwrites the client's buffer and contains exploit code arbitrary commands can be run on the client system.
The Chocoa IRC client has an unchecked buffer in the code that processes channel topics. If the server returns a topic that overwrites the client's buffer and contains exploit code arbitrary commands can be run on the client system.
Exploit / POC
Fujitsu Chocoa "Topic" Buffer Overflow Vulnerability
This exploit will open an instance of notepad on the target, with the autoexec.bat file loaded into it.
This exploit will open an instance of notepad on the target, with the autoexec.bat file loaded into it.
Solution / Fix
References
Fujitsu Chocoa "Topic" Buffer Overflow Vulnerability
References:
References:
- CHOCOA 1.0beta7R Overflow exploit on Windows9/NT (Shadow Penguin Security)