Bug#443544: CVE-2007-4584 stack based buffer overflow via long MODE command

2007-09-26 Thread Nico Golde
hi, i just want to add if someone is going to fix this it is not enough to just use strncpy and append 0 to the buffer since it segfaults with and without the patch in screen.c I currently have no idea why and how to fix this since I am lacking of bitchx internals. Here is a backtrace: #0 BX_

Bug#443544: CVE-2007-4584 stack based buffer overflow via long MODE command

2007-09-22 Thread Nico Golde
Package: ircii-pana Severity: grave Tags: security Hi, the following CVE was published for ircii-pana. CVE-2007-4584[0]: Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable. If yo