irc2 SERVER Command Argument Buffer Overflow Vulnerability
BID:6804
Info
irc2 SERVER Command Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 6804 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 1997 12:00AM |
| Updated: | Jun 30 1997 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to : Andy Church <[email protected]> |
| Vulnerable: |
irc2 irc2 2.8.21 DALnet Bahamut IRCd 4.4.10 DALnet Bahamut IRCd 4.4.5 |
| Not Vulnerable: |
DALnet Bahamut IRCd 4.6.7 DALnet Bahamut IRCd 4.6.5 DALnet Bahamut IRCd 4.4.11 |
Discussion
irc2 SERVER Command Argument Buffer Overflow Vulnerability
A buffer overflow condition has been reported for multiple irc daemons derived from the irc2 source.
The vulnerability is due to a lack of sufficient bounds checking on the server side 'SERVER' command. An attacker may, depending on the compiler and optimization settings used to create the binary, exploit this condition to manipulate stack based memory resulting in a denial of service condition or execution of attacker supplied arbitrary code. Arbitrary code would be executed in the security context of the ircd process.
A buffer overflow condition has been reported for multiple irc daemons derived from the irc2 source.
The vulnerability is due to a lack of sufficient bounds checking on the server side 'SERVER' command. An attacker may, depending on the compiler and optimization settings used to create the binary, exploit this condition to manipulate stack based memory resulting in a denial of service condition or execution of attacker supplied arbitrary code. Arbitrary code would be executed in the security context of the ircd process.
Exploit / POC
irc2 SERVER Command Argument Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
irc2 SERVER Command Argument Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.