5
CVSSv2

CVE-2011-5129

Published: 30/08/2012 Updated: 14/02/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Heap-based buffer overflow in XChat 2.8.9 and previous versions allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long response string.

Vulnerable Product Search on Vulmon Subscribe to Product

xchat xchat 2.8.7

xchat xchat 2.8.6

xchat xchat 2.8.1

xchat xchat 2.8.0

xchat xchat 1.3.12

xchat xchat 1.3.13

xchat xchat 2.8.8

xchat xchat 2.8.5

xchat xchat 1.4.3

xchat xchat 1.5.6

xchat xchat 1.3.11

xchat xchat 1.2.1

xchat xchat 1.8.9

xchat xchat 1.8.4

xchat xchat 1.8.1

xchat xchat 2.0.6

xchat xchat 1.9.8

xchat xchat 1.9.9

xchat xchat

xchat xchat 2.8.4

xchat xchat 2.8.3

xchat xchat 1.4.1

xchat xchat 1.4.2

xchat xchat 1.9.1

xchat xchat 1.9.0

xchat xchat 1.8.3

xchat xchat 1.8.6

xchat xchat 2.0.7

xchat xchat 2.0.8

xchat xchat 2.0.0

xchat xchat 2.0.1

xchat xchat 1.3.10

xchat xchat 1.8.8

xchat xchat 1.8.7

xchat xchat 1.8.2

xchat xchat 2.8.7b

xchat xchat 2.0.4

xchat xchat 2.0.5

xchat xchat 1.9.6

xchat xchat 1.9.7

xchat xchat 1.3.9

xchat xchat 1.4

xchat xchat 1.9.3

xchat xchat 1.9.2

xchat xchat 1.8.5

xchat xchat 1.8.0

xchat xchat 2.6.7

xchat xchat 2.0.2

xchat xchat 2.0.3

xchat xchat 1.9.4

xchat xchat 1.9.5

Vendor Advisories

Debian Bug report logs - #686454 CVE-2011-5129: xchat buffer overflow Package: xchat; Maintainer for xchat is Gianfranco Costamagna <locutusofborg@debianorg>; Source for xchat is src:xchat (PTS, buildd, popcon) Reported by: Raphael Geissert <geissert@debianorg> Date: Sat, 1 Sep 2012 18:48:01 UTC Severity: grave T ...

Exploits

#!/usr/bin/python # Exploit Title: XChat Heap Overflow DoS Proof of Concept # Date: June 2011 # Author: th3p4tri0t # Software Link: xchatorg/ # Version: <= 289 # This only works on XChat on KDE, I'm not sure about windows # It has been tested on Ubuntu (failed), Kubuntu, and Bactrack 5 # It is a heap overflow and is some sort of err ...