漏洞信息详情
X-Chat CTCP Ping任意远程IRC命令执行漏洞
- CNNVD编号:CNNVD-200206-079
- 危害等级: 高危
- CVE编号:
CVE-2002-0006
- 漏洞类型:
输入验证
- 发布时间:
2002-06-25
- 威胁类型:
远程
- 更新时间:
2005-05-02
- 厂 商:
xchat - 漏洞来源:
Published on the B… -
漏洞简介
含1.4.2版本和1.4.3版本默认配置的XChat 1.8.7版本及更早版本存在漏洞。远程攻击者可以像其他客户端借助调用CTCP PING的PRIVMSG命令中的编码字符执行任意IRC命令,该漏洞在设置percascii变量时扩展客户端响应中的字符。
漏洞公告
Updated versions of X-Chat are available.
X-Chat X-Chat 1.4
-
Red Hat xchat-1.8.7-1.62.0.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/xchat-1.8.7-1.62.0.alpha.rpm -
Red Hat xchat-1.8.7-1.62.0.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/xchat-1.8.7-1.62.0.i386.rpm -
Red Hat xchat-1.8.7-1.62.0.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/xchat-1.8.7-1.62.0.sparc.rpm -
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
X-Chat X-Chat 1.4.1
-
Mandrake xchat-1.8.7-1.2mdk.i586.rpmfor Mandrake 7.2
http://www.linux-mandrake.com/en/ftp.php3 -
Mandrake xchat-1.8.7-1.3mdk.i586.rpmfor Mandrake 7.1
http://www.linux-mandrake.com/en/ftp.php3 -
Mandrake xchat-1.8.7-1.3mdk.i586.rpmfor Mandrake Corporate Server 1.0.1
http://www.linux-mandrake.com/en/ftp.php3 -
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
X-Chat X-Chat 1.4.2
-
Conectiva xchat-1.4.2-5U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/xchat-1.4.2-5U50_1cl.i386
.rpm -
Conectiva xchat-1.4.2-5U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/xchat-1
.4.2-5U50_1cl.i386.rpm -
Conectiva xchat-1.4.2-5U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/xchat-1.
4.2-5U50_1cl.i386.rpm -
Conectiva xchat-1.4.2-5U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/xchat-1.4.2-5U51_1cl.i386
.rpm -
Red Hat xchat-1.8.7-1.70.0.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/xchat-1.8.7-1.70.0.alpha.rpm -
Red Hat xchat-1.8.7-1.70.0.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/xchat-1.8.7-1.70.0.i386.rpm -
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
X-Chat X-Chat 1.4.3
-
Conectiva xchat-1.4.3-8U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/xchat-1.4.3-8U60_1cl.i386
.rpm -
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
X-Chat X-Chat 1.6.3
-
Red Hat xchat-1.8.7-1.71.0.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/xchat-1.8.7-1.71.0.alpha.rpm -
Red Hat xchat-1.8.7-1.71.0.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/xchat-1.8.7-1.71.0.i386.rpm -
Red Hat xchat-1.8.7-1.71.0.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/xchat-1.8.7-1.71.0.ia64.rpm -
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
X-Chat X-Chat 1.6.4
-
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
X-Chat X-Chat 1.7.7
-
Conectiva xchat-1.8.7-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/xchat-1.8.7-1U70_1cl.i386
.rpm -
Conectiva xchat-gtk-1.8.7-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/xchat-gtk-1.8.7-1U70_1cl.
i386.rpm
X-Chat X-Chat 1.8
-
Mandrake xchat-1.8.7-1.1mdk.i586.rpmfor Mandrake 8.0 i586
http://www.linux-mandrake.com/en/ftp.php3 -
Mandrake xchat-1.8.7-1.1mdk.ppc.rpmfor Mandrake 8.0 ppc
http://www.linux-mandrake.com/en/ftp.php3
X-Chat X-Chat 1.8.1
-
Red Hat xchat-1.8.7-1.72.0.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/xchat-1.8.7-1.72.0.i386.rpm -
Red Hat xchat-1.8.7-1.72.0.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/xchat-1.8.7-1.72.0.ia64.rpm -
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
X-Chat X-Chat 1.8.2
-
Mandrake xchat-1.8.7-1.1mdk.i586.rpmfor Mandrake 8.1 i586
http://www.linux-mandrake.com/en/ftp.php3 -
Mandrake xchat-1.8.7-1.1mdk.ia64.rpmfor Mandrake 8.1 ia64
http://www.linux-mandrake.com/en/ftp.php3
X-Chat X-Chat 1.8.6
-
X-Chat X-Chat 1.8.7
http://www.xchat.org/download.html
参考网址
来源: DEBIAN
名称: DSA-099
链接:http://www.debian.org/security/2002/dsa-099
来源: BUGTRAQ
名称: 20020109 xchat IRC session hijacking vulnerability (versions 1.4.1, 1.4.2)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=101060676210255&w=2
来源: XF
名称: xchat-ctcp-ping-command(7856)
链接:http://xforce.iss.net/static/7856.php
来源: BID
名称: 3830
链接:http://www.securityfocus.com/bid/3830
来源: REDHAT
名称: RHSA-2002:005
链接:http://rhn.redhat.com/errata/RHSA-2002-005.html
来源: HP
名称: HPSBTL0201-016
链接:http://online.securityfocus.com/advisories/3806
来源: CONECTIVA
名称: CLA-2002:453
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000453