Remote Crash on irssi - core dumps - Possibly exploitable?
Lucius Rizzo <[email protected]> Wed, 26 Mar 2014 05:46:08 -0700
| Newsgroups | gmane.network.irc.irssi.user |
|---|---|
| Message-ID | <[email protected]> |
Hi everyone, I am running irssi 0.8.16-rc1 (20130915 1649) on NetBSD NetBSD t.Gt 6.1.2 NetBSD 6.1.2 (SMP-PROD1>) #0: Sat Dec 28 15:57:49 EST 2013 [email protected]:/usr/src/sys/arch/i386/compile/t_gt i386 I have never had problems until today when somone was able to crash my irssi which core dumped. I am not sure why irssi wasn't able to handle a flood and how someone remotely can do this. Is there anyone who might be able help? Here is the core dump: [8408:42 0:508] 01:42:15 Wed Mar 26 [[email protected]:/dev/pts/0 +2] ~ (2:508)$ !gd gdb /usr/pkg/bin/irssi irssi.core GNU gdb (GDB) 7.3.1 Copyright (C) 2011 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Type "show copying" and "show warranty" for details. This GDB was configured as "i486--netbsdelf". For bug reporting instructions, please see: <http://www.gnu.org/software/gdb/bugs/>... Reading symbols from /usr/pkg/bin/irssi...done. [New process 1] [New process 2] Core was generated by `irssi'. Program terminated with signal 11, Segmentation fault. #0 0x080be346 in flood_newmsg (server=0xba414000, level=4, nick=0xba45c001 "watchy--", host=0xba45c00a "[email protected]", target=0xba302040 "#LinuxWarez") at flood.c:196 196 flood = g_hash_table_lookup(mserver->floodlist, nick); (gdb) where #0 0x080be346 in flood_newmsg (server=0xba414000, level=4, nick=0xba45c001 "watchy--", host=0xba45c00a "[email protected]", target=0xba302040 "#LinuxWarez") at flood.c:196 #1 0x080be95e in flood_privmsg (server=0xba414000, data=0xba33420e "#LinuxWarez :im home from mma faggotys", nick=0xba45c001 "watchy--", addr=0xba45c00a "[email protected]") at flood.c:255 #2 0x080d6770 in signal_emit_real (rec=0xbb4390c0, params=<optimized out>, va=<optimized out>, first_hook=0xbb44dbe0) at signals.c:242 #3 0x080d6b54 in signal_emit (signal=0xba334200 "event privmsg", params=4) at signals.c:286 #4 0x0809fecf in irc_server_event (server=0xba414000, line=0xba45c024 "PRIVMSG #LinuxWarez :im home from mma faggotys", nick=0xba45c001 "watchy--", address=0xba45c00a "[email protected]") at irc.c:304 #5 0x080d6770 in signal_emit_real (rec=0xbb42efc0, params=<optimized out>, va=<optimized out>, first_hook=0xbb43e480) at signals.c:242 #6 0x080d6bc7 in signal_emit_id (signal_id=95, params=4) at signals.c:304 #7 0x0809fb74 in irc_parse_incoming_line (server=0xba414000, line=<optimized out>) at irc.c:358 #8 0x080d6770 in signal_emit_real (rec=0xbb43e4c0, params=<optimized out>, va=<optimized out>, first_hook=0xbb43e4e0) at signals.c:242 #9 0x080d6bc7 in signal_emit_id (signal_id=206, params=2) at signals.c:304 #10 0x0809fd95 in irc_parse_incoming (server=0xba414000) at irc.c:379 #11 0x080c944e in irssi_io_invoke (source=0xba404080, condition=G_IO_IN, data=0xba402380) at misc.c:54 #12 0xbb9eb67e in g_io_unix_dispatch () from /usr/pkg/lib/libglib-2.0.so.0 #13 0xbb9a9774 in g_main_context_dispatch () from /usr/pkg/lib/libglib-2.0.so.0 #14 0xbb9a9a94 in g_main_context_iterate.clone.5 () from /usr/pkg/lib/libglib-2.0.so.0 #15 0xbb9a9b8d in g_main_context_iteration () from /usr/pkg/lib/libglib-2.0.so.0 #16 0x0806db43 in main (argc=3, argv=0xbfbfe600) at irssi.c:356 (gdb) Thanks! -- | _o _ |_)o_ _ _ |_|_|(_||_|_> | \|/_/_(_) - Lucius.Tel -------------------------------------- ++ You can't take it with you -- ++ ++ especially when crossing a state line. ++