RQ Buffer Overflow Lets Remote Systems Crash the Client
|
|
SecurityTracker Alert ID: 1011055
|
|
SecurityTracker URL: http://securitytracker.com/id?1011055
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Aug 25 2004
|
Impact: Denial of service via network
|
Vendor Confirmed: Yes
|
Version(s): 0.9.4.16 and prior versions
|
Description: A vulnerability was reported in the &RQ IRC client. A remote user can cause the client to crash.
RdM-[YanDeX] reported on SECURITY.NNOV that a remote system can send a specially crafted authorization request to cause &RQ to crash.
|
Impact: A remote server can cause a connected client to crash.
|
Solution: The vendor's web site notes that software is no longer in development.
The vendor reportedly has an 'andrq.ini' file that is not vulnerable.
|
Vendor URL: www.rejetto.com/&RQ/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (Any)
|
Reported By: RdM-[YanDeX] <rdm-yandex@nnm.ru>
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|