mIRC < 6.0 Long Nickname Buffer Overflow

High Nessus Network Monitor Plugin ID 1861

Synopsis

The remote host is running a version of mIRC that is vulnerable to a buffer overflow attack.

Description

This issue is due to improper bounds checking of nicknames sent by the server. An excessively long nickname (200+) is capable of overwriting the stack. This issue is also exploitable via a webpage that can instruct the client to launch and to make a connection to the malicious web server. This may lead to full compromise of the host running the client software on some Windows systems.

Solution

Upgrade to version 6.0 or higher.

Plugin Details

Severity: High

ID: 1861

File Name: 1861.prm

Family: IRC Clients

Published: 2004/08/20

Modified: 2016/11/23

Dependencies: 1878

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSSv3

Base Score: 7.3

Temporal Score: 6.8

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:F/RL:O/RC:C

Reference Information

CVE: CVE-2002-0231

BID: 4027

OSVDB: 6404