andsome Posted October 28, 2003 Report Share Posted October 28, 2003 "It is never too late to learn what is always necessary to know." Lucius Annaeus Seneca (2BC-65AD); Roman philospher, statesman. - Vulnerability in version 6.12 of mIRC - Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)Madrid, October 27, 2003 - SecuriTeam has reported a security flaw in thelatest version of mIRC, the most popular Windows client used in InternetRelay Chat (IRC).By exploiting this vulnerability, an attacker could send a specially craftedquery which forces the mIRC client to close. This flaw only affects userthat minimize the DCC protocol dialog box (by default or manually). Theclient crashes when the attacker sends a file with an overlong name via DCCand the user opens this dialog box.Until a new version of mIRC that fixes this vulnerability is available,users can take one of several preventative measures. These include disablingall queries received via DCC -through the command '/ignore -wd *'- andenabling the 'auto-get file' option in the DCC menu. ------------------------------------------------------------The 5 viruses most frequently detected by Panda ActiveScan, Panda Software'sfree online scanner: 1) Parite.B; 2) Blaster; 3) Bugbear.B; 4) Gibe.C; 5)Blaster.E.------------------------------------------------------------To unsubscribe from Oxygen3 24h-365d, please visit:http://www.pandasoftware.com/unsubscribe.aspTo contact with Panda Software, please visit:http://www.pandasoftware.com/about/contact/------------------------------------------------------------ Quote Link to comment Share on other sites More sharing options...
Redhat Posted October 28, 2003 Report Share Posted October 28, 2003 Well I don't use mIRC, I use X-Chat on Linux, but one has to say this is the escond vulnerability recently found in mIRC I hope it's the last for now. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.