[VULN] A remote exploit in SILC software

Pekka Riikonen <[email protected]> Thu, 16 Oct 2003 15:35:08 +0200 (CEST)
Newsgroups gmane.network.silc.announce
Message-ID <[email protected]>
A vulnerability in the way generic SILC packet processing library handles
certain incoming packets could allow attacker to mount denial of service
attack against SILC software.

Vulnerability

By sending more than one packets at once where one packet invalidates the
socket connection in the parser callback an attacker can crash the program
due to insufficient checks for the validity of the socket connection after
the parser callback returns.

Systems Affected

SILC Toolkit 0.9.9 and older
SILC Server 0.9.13.1 and older
SILC Client 0.9.12.1 and older

Solution

Upgrade to the following or newer versions of the software.

SILC Toolkit 0.9.10
SILC Server 0.9.14
SILC Client 0.9.13

	Pekka
________________________________________________________________________
 Pekka Riikonen                                 priikone at silcnet.org
 Secure Internet Live Conferencing (SILC)       http://silcnet.org/
_________________________________________________________
Info:    http://lists.silcnet.org/listinfo/silc-announce
Archive: http://lists.silcnet.org/pipermail/silc-announce
FAQ:     http://silcnet.org/?page=faq