Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the my_strcat function by (1) ctcp_buffer, (2) cannot_join_channel, (3) status_make_printable for Statusbar drawing, (4) create_server_list, and possibly other functions.
Link | Tags |
---|---|
http://www.debian.org/security/2003/dsa-298 | vendor advisory |
http://www.securityfocus.com/bid/7098 | vdb entry |
http://www.debian.org/security/2003/dsa-291 | patch vendor advisory |
http://marc.info/?l=bugtraq&m=104766521328322&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=104808915402926&w=2 | mailing list |