Multiple vendor IRC (Internet Relay Chat) clients command execution
| irc-multiple-command-execution (35985) |
Description:
Multiple vendor IRC (Internet Relay Chat) clients could allow a remote attacker to execute arbitrary IRC commands caused by the improper filtering of id3 tags prior to passing them to XChat. By persuading a victim to play and announce a specially-crafted MP3 file, a remote attacker could exploit this vulnerability to execute arbitrary IRC commands in the victim's IRC client.
Platforms Affected:
- Colten Edwards, BitchX 1.0
- Craig Kelley, xchat-xmms 0.81
- FedoraProject, Fedora Core 6
- FlashTux, WeeChat 0.1
- FlashTux, WeeChat 1.1
- irssi, irssi prior to 0.8.11
- irssi, ixmmsa.pl 0.3
- irssi, l33tmusic.pl 2.00
- irssi, mpg123.pl 0.01
- irssi, ogg123.pl 0.01
- irssi, xmms.pl 2.0
- irssi, xmms2.pl 1.1.3
- irssi, xmmsinfo.pl 1.1.1.1
- Joe Thielen, XMMS-Control 0.33
- Konversation, Konversation 1.0.1
- mIRC, mIRC 2.49
- Peter Zelezny, Xchat 0.8.1 - 1.0
- XChat, a2x 0.0.1
- XChat, Another xmms-info script 1.0
- XChat, Disrok 1.0
- XChat, XMMS Remote Control Script 1.07
- XChat, xmms-thing 1.0
Remedy:
For irssi:
Upgrade to the latest version of irssi (0.8.11 or later), available from the irssi Web site. See References.
Consequences:
Gain Privileges
References:
- BitchX Web site, BitchX IRC Client at http://www.bitchx.com/.
- FlashTux Web site, WeeChat at http://weechat.flashtux.org/.
- Full-Disclosure Mailing List, Sun Aug 12 2007 - 12:02:24 CDT, Vulnerability in multiple "now playing" scripts for various IRC clients at http://archives.neohapsis.com/archives/fulldisclosure/2007-08/0211.html.
- irssi Web site, irssi at http://irssi.org/scripts/.
- Joe Thielen Web page, XMMS-Control at http://www.joethielen.com/xmms-control/.
- Konversation Web site, Konversation at http://konversation.berlios.de/.
- mIRC Home page, mIRC - An Internet Relay Chat program at http://www.mirc.com/index.html.
- wouter.coekaerts.be Web site, Vulnerability in multiple "now playing" scripts for various IRC clients at http://wouter.coekaerts.be/site/security/nowplaying.
- Xchat Web site, Xchat at http://xchat.org.
- Xchat-XMMS Web site, xchat-xmms at http://inconnu.isu.edu/~ink/new/projects/xchat-xmms/.
- BID-25281: Multiple IRC Client Now Playing Scripts Input Validation Vulnerability
- BID-25285: Universal Ircd Server Multiple Remote Vulnerabilities
- CVE-2007-4396: Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4397: Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-info script 1.0, (6) XChat-XMMS 0.8.1, and other unspecified scripts for XChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4398: Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4399: CRLF injection vulnerability in the xmms.bx 1.0 script for BitchX allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4400: CRLF injection vulnerability in the included media script in Konversation allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4401: Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4402: Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
- CVE-2007-4403: The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
- SA26454: XMMS-Control for XChat id3 Tag Input Validation Error
- SA26455: xchat-xmms for XChat id3 Tag Input Validation Error
- SA26456: Konversation Media Script id3 Tag Input Validation Error
- SA26457: now_playing.rb for weechat id3 Tag Input Validation Error
- SA26483: Multiple irssi Music Announcement Scripts id3 Tag Input Validation Error
- SA26484: xmms-thing for XChat id3 Tag Input Validation Error
- SA26485: XMMS Remote Control Script for XChat id3 Tag Input Validation Error
- SA26486: Disrok for XChat id3 Tag Input Validation Error
- SA26487: a2x for XChat id3 Tag Input Validation Error
- SA26488: Another xmms-info script for XChat id3 Tag Input Validation Error
- SA26489: xmms.bx for BitchX id3 Tag Input Validation Error
- SA26490: xmms.pl for weechat id3 Tag Input Validation Error
- SA26491: Advanced mIRC Integration Plugin id3 Tag Input Validation Error
Reported:
Aug 12, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
