IRCnet IRCD Local Buffer Overflow Vulnerability
BID:8817
Info
IRCnet IRCD Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8817 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0864 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery of this vulnerability has been credited to Piotr KUCHARSKI <[email protected]>. |
| Vulnerable: |
IRCNet IRCNet IRCD 2.10.3 p3 IRCNet IRCNet IRCD 2.10 |
| Not Vulnerable: |
IRCNet IRCNet IRCD 2.10.3 p4 |
Discussion
IRCnet IRCD Local Buffer Overflow Vulnerability
IRCnet IRCD has been reported prone to a buffer overflow vulnerability that may be exploited by local users. This issue may be exploited to crash the affected server. Although unconfirmed, due to the nature of this vulnerability it has been conjectured that a local attacker may also leverage this condition to potentially have arbitrary instructions executed in the context of the affected server.
IRCnet IRCD has been reported prone to a buffer overflow vulnerability that may be exploited by local users. This issue may be exploited to crash the affected server. Although unconfirmed, due to the nature of this vulnerability it has been conjectured that a local attacker may also leverage this condition to potentially have arbitrary instructions executed in the context of the affected server.
Exploit / POC
IRCnet IRCD Local Buffer Overflow Vulnerability
A proof of concept exploit for this issue has been made available.
A proof of concept exploit for this issue has been made available.
Solution / Fix
IRCnet IRCD Local Buffer Overflow Vulnerability
Solution:
OpenPKG has released an advisory (OpenPKG-SA-2003.045) that provides updates to address this issue. Detailed instructions on how to upgrade may be found in the advisory.
The vendor has released an update to address this issue.
IRCNet IRCNet IRCD 2.10
IRCNet IRCNet IRCD 2.10.3 p3
Solution:
OpenPKG has released an advisory (OpenPKG-SA-2003.045) that provides updates to address this issue. Detailed instructions on how to upgrade may be found in the advisory.
The vendor has released an update to address this issue.
IRCNet IRCNet IRCD 2.10
-
Conectiva ircd-2.10.3p3-27242U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/ircd-2.10.3p3-27242U90_2cl. i386.rpm -
IRCnet irc2.10.3p4.tgz
ftp://ftp.irc.org/irc/server/irc2.10.3p4.tgz
IRCNet IRCNet IRCD 2.10.3 p3
-
Conectiva ircd-2.10.3p3-27242U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/ircd-2.10.3p3-27242U90_2cl. i386.rpm -
IRCnet irc2.10.3p4.tgz
ftp://ftp.irc.org/irc/server/irc2.10.3p4.tgz -
OpenPKG ircd-2.10.3p3-1.2.1.src.rpm
ftp://ftp.openpkg.org/release/1.2/UPD/ircd-2.10.3p3-1.2.1.src.rpm -
OpenPKG ircd-2.10.3p3-1.3.1.src.rpm
ftp://ftp.openpkg.org/release/1.3/UPD/ircd-2.10.3p3-1.3.1.src.rpm -
OpenPKG ircd-2.10.3p5-20031013.src.rpm
ftp://ftp.openpkg.org/current/SRC/ircd-2.10.3p5-20031013.src.rpm
References
IRCnet IRCD Local Buffer Overflow Vulnerability
References:
References:
- buffer overflow in IRCD software (Piotr KUCHARSKI
) - Re: [CLA-2003:765] Conectiva Security Announcement - ircd (Florian Weimer
)