mIRC IRC URL Buffer Overflow Vulnerability
BID:8819
Info
mIRC IRC URL Buffer Overflow Vulnerability
| Bugtraq ID: | 8819 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2003 12:00AM |
| Updated: | Oct 13 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Phuong Nguyen <[email protected]>. |
| Vulnerable: |
Khaled Mardam-Bey mIRC 6.1 |
| Not Vulnerable: |
Khaled Mardam-Bey mIRC 6.11 |
Discussion
mIRC IRC URL Buffer Overflow Vulnerability
When mIRC is installed it registers a handler for a 'irc://' type of URL. Through these means, mIRC is invoked when an 'IRC URL' is followed.
mIRC has been reported prone to a buffer overflow vulnerability when handling malicious 'IRC URLs'. The issue likely presents itself due to a lack of sufficient boundary checks performed when IRC URL data is being copied into an insufficient buffer in memory. Ultimately a remote attacker may exploit this condition to execute arbitrary instructions in the context of the user running the affected client.
When mIRC is installed it registers a handler for a 'irc://' type of URL. Through these means, mIRC is invoked when an 'IRC URL' is followed.
mIRC has been reported prone to a buffer overflow vulnerability when handling malicious 'IRC URLs'. The issue likely presents itself due to a lack of sufficient boundary checks performed when IRC URL data is being copied into an insufficient buffer in memory. Ultimately a remote attacker may exploit this condition to execute arbitrary instructions in the context of the user running the affected client.
Exploit / POC
mIRC IRC URL Buffer Overflow Vulnerability
The following proof of concept has been supplied:
irc://[buffer]...... where's buffer >998 bytes
An exploit has been released:
The following proof of concept has been supplied:
irc://[buffer]...... where's buffer >998 bytes
An exploit has been released:
Solution / Fix
mIRC IRC URL Buffer Overflow Vulnerability
Solution:
The vendor has released an update to address this issue:
Khaled Mardam-Bey mIRC 6.1
Solution:
The vendor has released an update to address this issue:
Khaled Mardam-Bey mIRC 6.1
-
Khaled Mardam-Bey mirc611.exe
http://www.mirc.com/get.html