|
XChat DNS Command Character Stripping EXECL Vulnerability
XChat is a freely available, open source IRC client. It is available for the the Unix, Linux, and Microsoft Windows platforms. XChat does not filter the response from an IRC server when a /dns query is executed. Because of the method XChat uses to resolve hostnames, by passing the configured resolver and hostname to a shell, an IRC server may return a maliciously formatted response that executes arbitrary commands with the privileges of the IRC client. |
|
|
Privacy Statement |