[BUG SUB] silc-server 1.0.2 denial of service vulnerability - silc-server

"Frank Benkstein" <[email protected]>
Newsgroups gmane.network.silc.devel
Message-ID <[email protected]>
Software: silc-server
Version: 1.0.2
Operating System: Linux
Installation: source
Severity: critical

Description:

The current version of silc-server makes it possible
to crash a networks SILC router (or standalone server), when a new channel is created. All it takes
is to specify an invalid hmac algorithm name and no cipher algorithm name.
This results in an null pointer dereference in \'SILC_SERVER_CMD_FUNC(join)\' at
line 2444 in apps/silcd/command.c.


How to repeat:

/connect yourserver
/join nonexistent -hmac nonexistent


Remote Environment:

unspecified


Fix:

I posted a fix to the Gentoo Bug tracker:
http://bugs.gentoo.org/attachment.cgi?id=112279&action=view
_______________________________________________________________________
Info:    https://lists.silcnet.org/mailman/listinfo/silc-announce
Archive: https://lists.silcnet.org/pipermail/silc-announce
FAQ:     http://silcnet.org/support/faq/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.