Epic CTCP Nickname Server Message Buffer Overrun Vulnerability
BID:8999
Info
Epic CTCP Nickname Server Message Buffer Overrun Vulnerability
| Bugtraq ID: | 8999 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0328 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery is credited to Jeremy Nelson. |
| Vulnerable: |
Epic Epic4 1.1.11 Epic Epic4 1.1.10 Epic Epic4 1.1.7 .20020907 Epic Epic4 1.1.7 Epic Epic4 1.1.6 Epic Epic4 1.1.5 Epic Epic4 1.1.4 Epic Epic4 1.1.3 Epic Epic4 1.1.2 .20020219 Epic Epic4 1.0.1 Epic Epic4 pre2.003 Epic Epic4 pre2.002 |
| Not Vulnerable: | |
Discussion
Epic CTCP Nickname Server Message Buffer Overrun Vulnerability
A remotely exploitable buffer overrun has been reported in Epic. This issue may reportedly be exploited by a malicious server that supplies an overly long nickname in a CTCP messages, potentially allowing for execution of arbitrary code in the context of the client user. It may be also be possible for a malicious client to send such a message, but it is likely that the server will limit the length.
A remotely exploitable buffer overrun has been reported in Epic. This issue may reportedly be exploited by a malicious server that supplies an overly long nickname in a CTCP messages, potentially allowing for execution of arbitrary code in the context of the client user. It may be also be possible for a malicious client to send such a message, but it is likely that the server will limit the length.
Exploit / POC
Solution / Fix
Epic CTCP Nickname Server Message Buffer Overrun Vulnerability
Solution:
Debian has released an advisory (DSA 399-1) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released a security advisory (RHSA-2003-342) that includes fixes to address this issue. Users are advised to upgrade as soon as possible.
The vendor has released a patch.
Fixes:
Epic Epic4 pre2.002
Epic Epic4 pre2.003
Epic Epic4 1.0.1
Epic Epic4 1.1.10
Epic Epic4 1.1.11
Epic Epic4 1.1.2 .20020219
Epic Epic4 1.1.3
Epic Epic4 1.1.4
Epic Epic4 1.1.5
Epic Epic4 1.1.6
Epic Epic4 1.1.7 .20020907
Epic Epic4 1.1.7
Solution:
Debian has released an advisory (DSA 399-1) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released a security advisory (RHSA-2003-342) that includes fixes to address this issue. Users are advised to upgrade as soon as possible.
The vendor has released a patch.
Fixes:
Epic Epic4 pre2.002
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 pre2.003
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.0.1
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1 -
Red Hat epic-1.0.1-15.7.x.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/epic-1.0.1-15.7.x.i386.rpm -
Red Hat epic-1.0.1-15.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/epic-1.0.1-15.8.0.i386.rpm -
Red Hat epic-1.0.1-15.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/epic-1.0.1-15.9.i386.rpm
Epic Epic4 1.1.10
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.1.11
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.1.2 .20020219
-
Debian epic4_1.1.2.20020219-2.2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_alpha.deb -
Debian epic4_1.1.2.20020219-2.2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_arm.deb -
Debian epic4_1.1.2.20020219-2.2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_hppa.deb -
Debian epic4_1.1.2.20020219-2.2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_i386.deb -
Debian epic4_1.1.2.20020219-2.2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_ia64.deb -
Debian epic4_1.1.2.20020219-2.2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_m68k.deb -
Debian epic4_1.1.2.20020219-2.2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_mips.deb -
Debian epic4_1.1.2.20020219-2.2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_mipsel.deb -
Debian epic4_1.1.2.20020219-2.2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_powerpc.deb -
Debian epic4_1.1.2.20020219-2.2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_s390.deb -
Debian epic4_1.1.2.20020219-2.2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/epic4/epic4_1.1.2.20020 219-2.2_sparc.deb
Epic Epic4 1.1.3
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.1.4
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.1.5
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.1.6
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.1.7 .20020907
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
Epic Epic4 1.1.7
-
Epic alloca_underrun-patch-1
ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1
References
Epic CTCP Nickname Server Message Buffer Overrun Vulnerability
References:
References:
- Epic Homepage (Epic)
- RHSA-2003-342 (Red Hat)
- EPIC4 remote client-side stack-based overflow(exploit) (
)