XChat Server Strings Buffer Overflow Vulnerability
BID:7089
Info
XChat Server Strings Buffer Overflow Vulnerability
| Bugtraq ID: | 7089 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2003 12:00AM |
| Updated: | Mar 14 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
X-Chat X-Chat 2.0.1 |
| Not Vulnerable: | |
Discussion
XChat Server Strings Buffer Overflow Vulnerability
XChat IRC client has been reported vulnerable, under certain circumstances, to a buffer overflow condition.
Due to a lack sufficient bounds checking when copying server-supplied strings into internal buffers, it may be possible to trigger a buffer overflow.
A hostile IRC server may be able to exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
This vulnerability was reported to affect XChat version 2.0.1 other versions may also be affected.
XChat IRC client has been reported vulnerable, under certain circumstances, to a buffer overflow condition.
Due to a lack sufficient bounds checking when copying server-supplied strings into internal buffers, it may be possible to trigger a buffer overflow.
A hostile IRC server may be able to exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
This vulnerability was reported to affect XChat version 2.0.1 other versions may also be affected.
Exploit / POC
XChat Server Strings Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
XChat Server Strings Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
XChat Server Strings Buffer Overflow Vulnerability
References:
References:
- X-Chat (X-Chat)
- Buffer overflows in ircII-based clients (Timo Sirainen
)