[VULN] A remote exploit in SILC software
Pekka Riikonen <[email protected]> Thu, 16 Oct 2003 15:35:08 +0200 (CEST)
| Newsgroups | gmane.network.silc.announce |
|---|---|
| Message-ID | <[email protected]> |
A vulnerability in the way generic SILC packet processing library handles certain incoming packets could allow attacker to mount denial of service attack against SILC software. Vulnerability By sending more than one packets at once where one packet invalidates the socket connection in the parser callback an attacker can crash the program due to insufficient checks for the validity of the socket connection after the parser callback returns. Systems Affected SILC Toolkit 0.9.9 and older SILC Server 0.9.13.1 and older SILC Client 0.9.12.1 and older Solution Upgrade to the following or newer versions of the software. SILC Toolkit 0.9.10 SILC Server 0.9.14 SILC Client 0.9.13 Pekka ________________________________________________________________________ Pekka Riikonen priikone at silcnet.org Secure Internet Live Conferencing (SILC) http://silcnet.org/ _________________________________________________________ Info: http://lists.silcnet.org/listinfo/silc-announce Archive: http://lists.silcnet.org/pipermail/silc-announce FAQ: http://silcnet.org/?page=faq