New BitchX packages fix DoS and arbitrary code execution

Tuesday, May 20 2003 @ 12:05 AM EDT

Contributed by: William Reyor

According to a recent update from Debians security advisory board ,"[BitchX/ircii has a vulnerability that could allow]a malicious server to craft special reply strings, triggering the client to write beyond buffer boundaries or allocate a negative amount of memory. This could lead to a denial of service if the client only crashes, but may also lead to executing of arbitrary code under the user id of the chatting user."

See link for patch

Comments (0)


Topsight.net
http://www.topsight.net/article.php/20030520000548167