BitchX Mode Change Denial Of Service Vulnerability
BID:7551
Info
BitchX Mode Change Denial Of Service Vulnerability
| Bugtraq ID: | 7551 |
| Class: | Design Error |
| CVE: |
CVE-2003-0334 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2003 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | This vulnerability was discovered by powuh. |
| Vulnerable: |
BitchX IRC Client 1.0 c20cvs BitchX IRC Client 1.0 c19 BitchX IRC Client 1.0 c18 |
| Not Vulnerable: |
BitchX IRC Client 1.0 c20-cvs-05092003 |
Discussion
BitchX Mode Change Denial Of Service Vulnerability
A denial of service vulnerability has been reported for BitchX. It is possible to cause BitchX to crash when certain mode changes are made.
The precise details of this vulnerability are currently unknown. This BID will be updated as more information becomes available.
A denial of service vulnerability has been reported for BitchX. It is possible to cause BitchX to crash when certain mode changes are made.
The precise details of this vulnerability are currently unknown. This BID will be updated as more information becomes available.
Exploit / POC
BitchX Mode Change Denial Of Service Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
BitchX Mode Change Denial Of Service Vulnerability
Solution:
Mandrake has released an advisory (MDKSA-2003:069) and fixes for this issue. Further information relating to applying fixes can be found in the referenced advisory, fixes can be found below.
Conectiva has released an advisory (CLA-2003:655) and fixes for this issue. Links to fixed packages can be found in the attached advisory. Alternatively, users can use the apt tool:
apt-get update
apt-get upgrade
Fixes available:
BitchX IRC Client 1.0 c19
BitchX IRC Client 1.0 c20cvs
Solution:
Mandrake has released an advisory (MDKSA-2003:069) and fixes for this issue. Further information relating to applying fixes can be found in the referenced advisory, fixes can be found below.
Conectiva has released an advisory (CLA-2003:655) and fixes for this issue. Links to fixed packages can be found in the attached advisory. Alternatively, users can use the apt tool:
apt-get update
apt-get upgrade
Fixes available:
BitchX IRC Client 1.0 c19
-
Mandrake BitchX-1.0-0.c19.3.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake BitchX-1.0-0.c19.3.1mdk.src.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake BitchX-1.0-0.c19.4.1mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake BitchX-1.0-0.c19.4.1mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake BitchX-1.0-0.c19.4.1mdk.src.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake BitchX-1.0-0.c19.4.1mdk.src.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php
BitchX IRC Client 1.0 c20cvs
-
BitchX bx1.0c20-cvs-05092003.tar.gz
ftp://ftp.bitchx.org/pub/BitchX/cvs-snapshot/bx1.0c20-cvs-05092003.tar .gz
References
BitchX Mode Change Denial Of Service Vulnerability
References:
References:
- Project Homepage (BitchX)
- BitchX: Crash when channel modes change (Rob Andrews
)