EPIC PRIVMSG Remote Heap Corruption Vulnerability
BID:7088
Info
EPIC PRIVMSG Remote Heap Corruption Vulnerability
| Bugtraq ID: | 7088 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2003 12:00AM |
| Updated: | Mar 14 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
Epic Epic4 1.1.7 .20020907 Epic Epic4 1.0.1 Epic Epic 3.0 .004 |
| Not Vulnerable: | |
Discussion
EPIC PRIVMSG Remote Heap Corruption Vulnerability
A vulnerability has been discovered in EPIC and EPIC4. The problem occurs due to insufficient bounds checking on data interchanged between clients. Specifically, by using the PRIVMSG command to send a message of excessive length to a vulnerable client, it may be possible to corrupt the processes heap memory.
Successful exploitation of this issue would likely cause the vulnerable client to crash. Although it has not yet been confirmed, there is a possibility that this issue can be exploited to execute arbitrary commands on target system.
A vulnerability has been discovered in EPIC and EPIC4. The problem occurs due to insufficient bounds checking on data interchanged between clients. Specifically, by using the PRIVMSG command to send a message of excessive length to a vulnerable client, it may be possible to corrupt the processes heap memory.
Successful exploitation of this issue would likely cause the vulnerable client to crash. Although it has not yet been confirmed, there is a possibility that this issue can be exploited to execute arbitrary commands on target system.
Exploit / POC
EPIC PRIVMSG Remote Heap Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EPIC PRIVMSG Remote Heap Corruption Vulnerability
Solution:
Debian has issued advisories DSA-287-1 and DSA-298-1 for EPIC and EPIC4 respectively. Information about obtaining and applying the fixes is contained in the advisories. Users of the apt-get system are advised to issue the following commands to upgrade systems:
apt-get update
apt-get upgrade
Fixes available:
Epic Epic4 1.0.1
Solution:
Debian has issued advisories DSA-287-1 and DSA-298-1 for EPIC and EPIC4 respectively. Information about obtaining and applying the fixes is contained in the advisories. Users of the apt-get system are advised to issue the following commands to upgrade systems:
apt-get update
apt-get upgrade
Fixes available:
Epic Epic4 1.0.1
-
Slackware epic4-1.0.1-i386-3.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/e pic4-1.0.1-i386-3.tgz -
Slackware epic4-1.0.1-i386-3.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/e pic4-1.0.1-i386-3.tgz
References
EPIC PRIVMSG Remote Heap Corruption Vulnerability
References:
References:
- Epic Homepage (Epic)
- Buffer overflows in ircII-based clients (Timo Sirainen
)