|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
A local overflow exists in mIRC. The product fails to check bounds for font command resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution with the current user privileges resulting in a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Technical |
The vendor notes: "As far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC. The author of the report indicates that any malicious software on your computer can modify your mIRC settings to cause mIRC to crash. But if you have malicious software on your computer, you've already compromised your security..."
|
|
Solution |
Upgrade to version 6.17 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
mIRC
 |
6.16 |
|
|
|
|
Credit |
- Jordi Corrales - jordi
shellsec.net - Shell Security
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|