ircII Client-Side Private Message Handling Memory Corruption Vulnerability
BID:7094
Info
ircII Client-Side Private Message Handling Memory Corruption Vulnerability
| Bugtraq ID: | 7094 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2003 12:00AM |
| Updated: | Mar 14 2003 12:00AM |
| Credit: | Discovery is credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
ircII Project ircII 20021103 ircII Project ircII 20020912 ircII Project ircII 20020403 |
| Not Vulnerable: |
ircII Project ircII 20030313 |
Discussion
ircII Client-Side Private Message Handling Memory Corruption Vulnerability
A buffer overflow vulnerability has been reported in ircII. This issue is due to insufficient bounds checking of server-supplied private messages data and may potentially result in a denial of service in the client software. Though unconfirmed, exploitation may also allow for execution of arbitrary code in the context of the client.
This issue was reported in ircII build 20020912. Other versions may also be affected.
A buffer overflow vulnerability has been reported in ircII. This issue is due to insufficient bounds checking of server-supplied private messages data and may potentially result in a denial of service in the client software. Though unconfirmed, exploitation may also allow for execution of arbitrary code in the context of the client.
This issue was reported in ircII build 20020912. Other versions may also be affected.
Exploit / POC
ircII Client-Side Private Message Handling Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ircII Client-Side Private Message Handling Memory Corruption Vulnerability
Solution:
This issues was addressed in ircII 20030313. Users are advised to upgrade.
ircII Project ircII 20020912
ircII Project ircII 20020403
ircII Project ircII 20021103
Solution:
This issues was addressed in ircII 20030313. Users are advised to upgrade.
ircII Project ircII 20020912
-
ircII Project ircii-20030313
ftp://ircii.warped.com/pub/ircII/
ircII Project ircII 20020403
-
ircII Project ircii-20030313
ftp://ircii.warped.com/pub/ircII/ -
OpenPKG ircii-20020403-1.1.1.src.rpm
ftp://ftp.openpkg.org/release/1.1/UPD/ircii-20020403-1.1.1.src.rpm
ircII Project ircII 20021103
-
ircII Project ircii-20030313
ftp://ircii.warped.com/pub/ircII/ -
OpenPKG ircii-20021103-1.2.1.src.rpm
ftp://ftp.openpkg.org/release/1.2/UPD/ircii-20021103-1.2.1.src.rpm
References
ircII Client-Side Private Message Handling Memory Corruption Vulnerability
References:
References:
- ircII Homepage (ircII Project)
- Buffer overflows in ircII-based clients (Timo Sirainen
)