20000704 BitchX exploit possibly waiting to happen, certain DoSmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-07/0026.html CVE-2000-0594
BitchX IRC Client 75p1/75p3/1.0 c16 - '/INVITE' Format String
Record summary
CVE-2000-0594 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBitchX IRC Client 75p1/75p3/1.0 c16 - '/INVITE' Format StringExploitDB exploitby RaiSeNot analyzed1 file
References
1020000707 CONECTIVA LINUX SECURITY ANNOUNCEMENT - BitchXmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-07/0098.html 20000707 BitchX updatemailing list
http://archives.neohapsis.com/archives/bugtraq/2000-07/0105.html FreeBSD-SA-00:32Vendor advisory
http://archives.neohapsis.com/archives/freebsd/2000-07/0042.html 20000704 BitchX /ignore bugmailing list
http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0018.html CSSA-2000-022.0Vendor advisory
http://www.calderasystems.com/support/security/advisories/CSSA-2000-022.0.txt RHSA-2000:042Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-042.html 1436vdb entry
http://www.securityfocus.com/bid/1436 irc-bitchx-invite-dos(4897)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/4897 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0594