Add to Favorites
Hosting Discussion
 

forgot password?


Reply


Old
  Post #1 (permalink)   02-05-2002, 11:18 AM
HD Addict
 
Homer's Avatar
 
Join Date: Jan 2002
Posts: 122

Status: Homer is offline
A security vulnerability has been found in the popular IRC client mIRC.
The flaw allows a rogue/hacked IRC server to execute arbitary code on
the victims machine. Allowing the attacker to gain full control of the
victims computer. This bug affects all versions of mIRC upto and
including version 5.91.

An error exists in mIRC's handling of certain messages from the server,
making it possible to overflow a static buffer. With carefully constructed
messages arbitary code can be executed.

The flaw must be exploited by a rogue server, however it is possible to
cause a user to unknowingly connect to a server. If a webpage is viewed
in Internet Explorer which contains specific code mIRC will attempt to
connect to a server, sometimes without prompting the user for conformation.
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On