Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

XChat DNS Command Character Stripping EXECL Vulnerability

XChat is a freely available, open source IRC client. It is available for the the Unix, Linux, and Microsoft Windows platforms.

XChat does not filter the response from an IRC server when a /dns query is executed. Because of the method XChat uses to resolve hostnames, by passing the configured resolver and hostname to a shell, an IRC server may return a maliciously formatted response that executes arbitrary commands with the privileges of the IRC client.







 

Privacy Statement
Copyright 2008, SecurityFocus