ircII Status_Make_Printable Memory Corruption Vulnerability
BID:7098
Info
ircII Status_Make_Printable Memory Corruption Vulnerability
| Bugtraq ID: | 7098 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2003 12:00AM |
| Updated: | Mar 14 2003 12:00AM |
| Credit: | Discovery is credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
ircII Project ircII 4.4 M ircII Project ircII 20021103 ircII Project ircII 20020912 ircII Project ircII 20020403 ircII Project ircII 20020322 |
| Not Vulnerable: |
ircII Project ircII 20030313 |
Discussion
ircII Status_Make_Printable Memory Corruption Vulnerability
A buffer overflow vulnerability has been reported in ircII. The vulnerability is related to the way ircII refreshes its status bar. Some functions do not properly account for some control characters when attempting to refresh the status bar.
This issue is exploitable by a malicious IRC server that sends an overly long response to the vulnerable ircII client. As the client does not make proper checks for control characters when updating the status bar, it will result in the corruption of sensitive memory with attacker-supplied values.
This will cause the client to behave in an unpredictable manner and possibly execute attacker-supplied code.
This issue was reported in ircII build 20020912. Other versions may also be affected.
A buffer overflow vulnerability has been reported in ircII. The vulnerability is related to the way ircII refreshes its status bar. Some functions do not properly account for some control characters when attempting to refresh the status bar.
This issue is exploitable by a malicious IRC server that sends an overly long response to the vulnerable ircII client. As the client does not make proper checks for control characters when updating the status bar, it will result in the corruption of sensitive memory with attacker-supplied values.
This will cause the client to behave in an unpredictable manner and possibly execute attacker-supplied code.
This issue was reported in ircII build 20020912. Other versions may also be affected.
Exploit / POC
ircII Status_Make_Printable Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ircII Status_Make_Printable Memory Corruption Vulnerability
Solution:
This issue was addressed in ircII 20030313. Users are advised to upgrade.
Debian has released an advisory to address this issue. Links to updated packages are located in the advisory.
ircII Project ircII 20020912
ircII Project ircII 20020403
ircII Project ircII 20020322
ircII Project ircII 20021103
ircII Project ircII 4.4 M
Solution:
This issue was addressed in ircII 20030313. Users are advised to upgrade.
Debian has released an advisory to address this issue. Links to updated packages are located in the advisory.
ircII Project ircII 20020912
-
ircII Project ircii-20030313
ftp://ircii.warped.com/pub/ircII/
ircII Project ircII 20020403
-
ircII Project ircii-20030313
ftp://ircii.warped.com/pub/ircII/ -
OpenPKG ircii-20020403-1.1.1.src.rpm
ftp://ftp.openpkg.org/release/1.1/UPD/ircii-20020403-1.1.1.src.rpm
ircII Project ircII 20020322
-
Debian ircii_20020322-1.1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_alpha.deb -
Debian ircii_20020322-1.1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_arm.deb -
Debian ircii_20020322-1.1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_hppa.deb -
Debian ircii_20020322-1.1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_i386.deb -
Debian ircii_20020322-1.1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_ia64.deb -
Debian ircii_20020322-1.1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_m68k.deb -
Debian ircii_20020322-1.1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_mips.deb -
Debian ircii_20020322-1.1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_powerpc.deb -
Debian ircii_20020322-1.1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_s390.deb -
Debian ircii_20020322-1.1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/i/ircii/ircii_20020322-1. 1_sparc.deb
ircII Project ircII 20021103
-
ircII Project ircii-20030313
ftp://ircii.warped.com/pub/ircII/ -
OpenPKG ircii-20021103-1.2.1.src.rpm
ftp://ftp.openpkg.org/release/1.2/UPD/ircii-20021103-1.2.1.src.rpm
ircII Project ircII 4.4 M
-
Debian ircii_4.4M-1.1_alpha.deb
Debian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/i/ircii/ircii_4.4M-1.1_al pha.deb -
Debian ircii_4.4M-1.1_arm.deb
Debian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/i/ircii/ircii_4.4M-1.1_ar m.deb -
Debian ircii_4.4M-1.1_i386.deb
Debian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/i/ircii/ircii_4.4M-1.1_i3 86.deb -
Debian ircii_4.4M-1.1_m68k.deb
Debian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/i/ircii/ircii_4.4M-1.1_m6 8k.deb -
Debian ircii_4.4M-1.1_powerpc.deb
Debian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/i/ircii/ircii_4.4M-1.1_po werpc.deb -
Debian ircii_4.4M-1.1_sparc.deb
Debian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/i/ircii/ircii_4.4M-1.1_sp arc.deb
References
ircII Status_Make_Printable Memory Corruption Vulnerability
References:
References:
- Buffer overflows in ircII-based clients (Timo Sirainen
)