Epic CTCP Nickname Server Message缓冲区溢出漏洞

漏洞信息详情

Epic CTCP Nickname Server Message缓冲区溢出漏洞

漏洞简介

EPIC IRC Client (EPIC4) pre2.002, pre2.003,和可能的更新版本存在漏洞。远程恶意IRC服务器借助超大昵称的CTCP请求导致服务拒绝(崩溃)并可能执行任意代码,该漏洞可以导致不正确长度计算。

漏洞公告

Debian has released an advisory (DSA 399-1) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released a security advisory (RHSA-2003-342) that includes fixes to address this issue. Users are advised to upgrade as soon as possible.
The vendor has released a patch.
Fixes:
Epic Epic4 pre2.002

Epic Epic4 pre2.003

Epic Epic4 1.0.1

Epic Epic4 1.1.10

Epic Epic4 1.1.11

Epic Epic4 1.1.2 .20020219

Epic Epic4 1.1.3

Epic Epic4 1.1.4

Epic Epic4 1.1.5

Epic Epic4 1.1.6

Epic Epic4 1.1.7 .20020907

Epic Epic4 1.1.7

参考网址

来源: ftp.prbh.org
链接:ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1

来源: REDHAT
名称: RHSA-2003:342
链接:http://www.redhat.com/support/errata/RHSA-2003-342.html

来源: DEBIAN
名称: DSA-399
链接:http://www.debian.org/security/2003/dsa-399

来源: DEBIAN
名称: DSA-306
链接:http://www.debian.org/security/2003/dsa-306

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享