Multiple vendor IRC (Internet Relay Chat) clients command execution
| irc-multiple-command-execution (35985) |
Description:
Multiple vendor IRC (Internet Relay Chat) clients could allow a remote attacker to execute arbitrary IRC commands caused by the improper filtering of id3 tags prior to passing them to XChat. By persuading a victim to play and announce a specially-crafted MP3 file, a remote attacker could exploit this vulnerability to execute arbitrary IRC commands in the victim's IRC client.
*CVSS:
| Base Score: | 2.8 |
| Access Vector: | Remote |
| Access Complexity: | High |
| Authentication: | Not Required |
| Confidentiality Impact: | None |
| Integrity Impact: | Partial |
| Availability Impact: | None |
| Temporal Score: | 2.4 |
| Exploitability: | High |
| Remediation Level: | Official-Fix |
| Report Confidence: | Confirmed |
Consequences:
Gain Privileges
Remedy:
For irssi:
Upgrade to the latest version of irssi (0.8.11 or later), available from the irssi Web site. See References.
References:
- BitchX Web site: BitchX IRC Client.
- FlashTux Web site: WeeChat.
- Full-Disclosure Mailing List, Sun Aug 12 2007 - 12:02:24 CDT: Vulnerability in multiple "now playing" scripts for various IRC clients.
- irssi Web site: irssi.
- Joe Thielen Web page: XMMS-Control.
- Konversation Web site: Konversation.
- mIRC Home page: mIRC - An Internet Relay Chat program.
- wouter.coekaerts.be Web site: Vulnerability in multiple "now playing" scripts for various IRC clients.
- Xchat Web site: Xchat.
- Xchat-XMMS Web site: xchat-xmms.
- BID-25281: Multiple IRC Client Now Playing Scripts Input Validation Vulnerability
- BID-25285: Universal Ircd Server Multiple Remote Vulnerabilities
- CVE-2007-4396: Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4397: Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-info script 1.0, (6) XChat-XMMS 0.8.1, and other unspecified scripts for XChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4398: Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4399: CRLF injection vulnerability in the xmms.bx 1.0 script for BitchX allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4400: CRLF injection vulnerability in the included media script in Konversation allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4401: Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
- CVE-2007-4402: Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
- CVE-2007-4403: The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
- SA26454: XMMS-Control for XChat id3 Tag Input Validation Error
- SA26455: xchat-xmms for XChat id3 Tag Input Validation Error
- SA26456: Konversation Media Script id3 Tag Input Validation Error
- SA26457: now_playing.rb for weechat id3 Tag Input Validation Error
- SA26483: Multiple irssi Music Announcement Scripts id3 Tag Input Validation Error
- SA26484: xmms-thing for XChat id3 Tag Input Validation Error
- SA26485: XMMS Remote Control Script for XChat id3 Tag Input Validation Error
- SA26486: Disrok for XChat id3 Tag Input Validation Error
- SA26487: a2x for XChat id3 Tag Input Validation Error
- SA26488: Another xmms-info script for XChat id3 Tag Input Validation Error
- SA26489: xmms.bx for BitchX id3 Tag Input Validation Error
- SA26490: xmms.pl for weechat id3 Tag Input Validation Error
- SA26491: Advanced mIRC Integration Plugin id3 Tag Input Validation Error
Platforms Affected:
- Colten Edwards BitchX 1.0
- Craig Kelley xchat-xmms 0.81
- FedoraProject Fedora Core 6
- FlashTux WeeChat 0.1
- FlashTux WeeChat 1.1
- irssi irssi prior to 0.8.11
- irssi ixmmsa.pl 0.3
- irssi l33tmusic.pl 2.00
- irssi mpg123.pl 0.01
- irssi ogg123.pl 0.01
- irssi xmms.pl 2.0
- irssi xmms2.pl 1.1.3
- irssi xmmsinfo.pl 1.1.1.1
- Joe Thielen XMMS-Control 0.33
- Konversation Konversation 1.0.1
- mIRC mIRC 2.49
- Peter Zelezny XChat 0.8.1 - 1.0
- XChat a2x 0.0.1
- XChat Another xmms-info script 1.0
- XChat Disrok 1.0
- XChat XMMS Remote Control Script 1.07
- XChat xmms-thing 1.0
Reported:
Aug 12, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
