XChat: malformed dcc send request denial of service
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200312-06 / xchat |
| Release Date |
December 14, 2003 |
| Latest Revision |
December 14, 2003: 01 |
| Impact |
medium |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-irc/xchat |
=
2.0.6 |
>=
2.0.6-r1 |
All supported architectures
|
Related bugreports:
#35623
Synopsis
A bug in XChat could allow malformed dcc send requests to cause a denial of
service.
2.
Impact Information
Background
XChat is a multiplatform IRC client.
Description
There is a remotely exploitable bug in XChat 2.0.6 that could lead to a
denial of service attack. Gentoo wishes to thank lloydbates for discovering
this bug, as well as jcdutton and rac for submitting patches to fix the bug.
Impact
A malformed DCC packet sent by a remote attacker can cause XChat to crash.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
For Gentoo users, xchat-2.0.6 was marked ~arch (unstable) for most
architectures. Since it was never marked as stable in the portage tree,
only xchat users who have explictly added the unstable keyword to
ACCEPT_KEYWORDS are affected. Users may updated affected machines to the
patched version of xchat using the following commands:
Code Listing 3.1: Resolution |
# emerge sync
# emerge -pv '>=net-irc/xchat-2.0.6-r1'
# emerge '>=net-irc/xchat-2.0.6-r1'
# emerge clean
|
This assumes that users are running with ACCEPT_KEYWORDS enabled for their
architecture.
4.
References
|