Bahamut IRCd Remote Format String Vulnerability
BID:8038
Info
Bahamut IRCd Remote Format String Vulnerability
| Bugtraq ID: | 8038 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2003 12:00AM |
| Updated: | Jun 26 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to an anonymous 0xbadc0ded.org affiliate. |
| Vulnerable: |
methane methane IRCd 0.1.1 ircd-RU! ircd-RU! 1.0.6 -release ircd-RU! ircd-RU! 1.0.6 -03-stable ircd-RU! ircd-RU! 1.0.6 -02-stable ircd-RU! ircd-RU! 1.0.6 -01-stable digatech digatech IRCd 1.2.1 DALnet Bahamut IRCd 1.4.35 andromede.net AndromedeIRCd 1.2.3 -Release |
| Not Vulnerable: |
ircd-RU! ircd-RU! 1.0.6 -04-stable |
Discussion
Bahamut IRCd Remote Format String Vulnerability
Behamut IRCd has been reported prone to remotely exploitable format string vulnerability.
The issue presents itself when Behamut is compiled with DEBUGMODE defined. Reportedly a remote attacker may send malicious format specifiers to trigger an error. By passing specially crafted format specifiers through the IRC session, a remote attacker could potentially corrupt process memory and may have the ability to execute arbitrary code with the privileges of the affected daemon.
It should be noted that IRC daemons that are derived from the Behamut source have also been reported vulnerable.
Behamut IRCd has been reported prone to remotely exploitable format string vulnerability.
The issue presents itself when Behamut is compiled with DEBUGMODE defined. Reportedly a remote attacker may send malicious format specifiers to trigger an error. By passing specially crafted format specifiers through the IRC session, a remote attacker could potentially corrupt process memory and may have the ability to execute arbitrary code with the privileges of the affected daemon.
It should be noted that IRC daemons that are derived from the Behamut source have also been reported vulnerable.
Exploit / POC
Bahamut IRCd Remote Format String Vulnerability
The following proof of concept has been supplied by [email protected]:
The following proof of concept has been supplied by [email protected]:
Solution / Fix
Bahamut IRCd Remote Format String Vulnerability
Solution:
The following fixes are available:
ircd-RU! ircd-RU! 1.0.6 -03-stable
ircd-RU! ircd-RU! 1.0.6 -01-stable
ircd-RU! ircd-RU! 1.0.6 -release
ircd-RU! ircd-RU! 1.0.6 -02-stable
Solution:
The following fixes are available:
ircd-RU! ircd-RU! 1.0.6 -03-stable
-
ircd-RU! ircd-RU-1.0.6-04-stable.tar.gz
ftp://ftp.ircd.ru/pub/ircd-RU/ircd-RU-1.0.6-04-stable.tar.gz
ircd-RU! ircd-RU! 1.0.6 -01-stable
-
ircd-RU! ircd-RU-1.0.6-04-stable.tar.gz
ftp://ftp.ircd.ru/pub/ircd-RU/ircd-RU-1.0.6-04-stable.tar.gz
ircd-RU! ircd-RU! 1.0.6 -release
-
ircd-RU! ircd-RU-1.0.6-04-stable.tar.gz
ftp://ftp.ircd.ru/pub/ircd-RU/ircd-RU-1.0.6-04-stable.tar.gz
ircd-RU! ircd-RU! 1.0.6 -02-stable
-
ircd-RU! ircd-RU-1.0.6-04-stable.tar.gz
ftp://ftp.ircd.ru/pub/ircd-RU/ircd-RU-1.0.6-04-stable.tar.gz
References
Bahamut IRCd Remote Format String Vulnerability
References:
References:
- Advisory #01 - 2003/06/26 - Bahamut IRCd <= 1.4.35 and others (0xbadc0ded)
- AndromedeIRCd 1.2.1 Homepage (Andromede)
- Azzurra Bahamut IPv6 - SSL Unofficial Patch (Bahamut)
- Bahamut IRCd Homepage (DALnet)
- ircd-RU! Homepage (ircd-RU!)
- Re: Bahamut IRCd <= 1.4.35 and several derived daemons (Roman Bogorodskiy
) - Re: Bahamut IRCd <= 1.4.35 and several derived daemons (Barnaba Marcello
)