BitchX Malformed RPL_NAMREPLY Denial Of Service Vulnerability
BID:6880
Info
BitchX Malformed RPL_NAMREPLY Denial Of Service Vulnerability
| Bugtraq ID: | 6880 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2003 12:00AM |
| Updated: | Feb 18 2003 12:00AM |
| Credit: | Discovery credited to <[email protected]>. |
| Vulnerable: |
BitchX IRC Client 1.0 c20cvs BitchX IRC Client 1.0 c19 BitchX IRC Client 1.0 c16 BitchX IRC Client 75p3 |
| Not Vulnerable: |
BitchX IRC Client 1.0 c18 |
Discussion
BitchX Malformed RPL_NAMREPLY Denial Of Service Vulnerability
It has been reported that BitchX does not properly handle some types of replies contained in the RPL_NAMREPLY numeric. When a malformed reply is received by the client, the client crashes, resulting in a denial of service.
It has been reported that BitchX does not properly handle some types of replies contained in the RPL_NAMREPLY numeric. When a malformed reply is received by the client, the client crashes, resulting in a denial of service.
Exploit / POC
BitchX Malformed RPL_NAMREPLY Denial Of Service Vulnerability
An exploit has been contributed by <[email protected]>:
An exploit has been contributed by <[email protected]>:
Solution / Fix
BitchX Malformed RPL_NAMREPLY Denial Of Service Vulnerability
Solution:
Gentoo Linux have advised users who are running 'net-irc/bitchx' upgrade to bitchx-1.0.19-r4 as follows:
emerge sync
emerge -u bitchx
emerge clean
Solution:
Gentoo Linux have advised users who are running 'net-irc/bitchx' upgrade to bitchx-1.0.19-r4 as follows:
emerge sync
emerge -u bitchx
emerge clean