vendor:
BNC's IRC Proxy
by:
jamez and dumped from sekure SDI
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: BNC's IRC Proxy
Affected Version From: 2.2.2004
Affected Version To: 2.2.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:bnc:bnc
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
1999
BNC’s IRC Proxy Buffer Overflow Vulnerability
BNC's IRC Proxy is used as a gateway to an IRC server. A buffer stores a username which arguments the program's USER command. User-supplied input to this buffer is improperly checked for length. As a result, the excessive data copied onto the stack can overwrite critical parts of the stack frame such as the calling functions' return address. If properly exploited, this can yield root privilege to the attacker.
Mitigation:
Input validation should be used to prevent buffer overflows.