vendor:
BitchX
by:
panasync and hellman
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: BitchX
Affected Version From: BitchX-75p3
Affected Version To: BitchX-1.0c20cvs
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003
BitchX Denial of Service Vulnerability
It has been reported that BitchX does not properly handle some types of replies contained in the RPL_NAMREPLY numeric. When a malformed reply is received by the client, the client crashes, resulting in a denial of service.
Mitigation:
In function funny_namreply(), add in a check to ensure that Args[1] and Args[2] are not NULL before proceeding.