Multiple vendor IRC (Internet Relay Chat) clients command execution

irc-multiple-command-execution (35985) The risk level is classified as MediumMedium Risk

Description:

Multiple vendor IRC (Internet Relay Chat) clients could allow a remote attacker to execute arbitrary IRC commands caused by the improper filtering of id3 tags prior to passing them to XChat. By persuading a victim to play and announce a specially-crafted MP3 file, a remote attacker could exploit this vulnerability to execute arbitrary IRC commands in the victim's IRC client.

*CVSS:

Base Score: 2.8
  Access Vector: Remote
  Access Complexity: High
  Authentication: Not Required
  Confidentiality Impact: None
  Integrity Impact: Partial
  Availability Impact: None
 
Temporal Score: 2.4
  Exploitability: High
  Remediation Level: Official-Fix
  Report Confidence: Confirmed

Consequences:

Gain Privileges

Remedy:

For irssi:
Upgrade to the latest version of irssi (0.8.11 or later), available from the irssi Web site. See References.

References:

  • BitchX Web site: BitchX IRC Client.
  • FlashTux Web site: WeeChat.
  • Full-Disclosure Mailing List, Sun Aug 12 2007 - 12:02:24 CDT: Vulnerability in multiple "now playing" scripts for various IRC clients.
  • irssi Web site: irssi.
  • Joe Thielen Web page: XMMS-Control.
  • Konversation Web site: Konversation.
  • mIRC Home page: mIRC - An Internet Relay Chat program.
  • wouter.coekaerts.be Web site: Vulnerability in multiple "now playing" scripts for various IRC clients.
  • Xchat Web site: Xchat.
  • Xchat-XMMS Web site: xchat-xmms.
  • BID-25281: Multiple IRC Client Now Playing Scripts Input Validation Vulnerability
  • BID-25285: Universal Ircd Server Multiple Remote Vulnerabilities
  • CVE-2007-4396: Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
  • CVE-2007-4397: Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-info script 1.0, (6) XChat-XMMS 0.8.1, and other unspecified scripts for XChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
  • CVE-2007-4398: Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
  • CVE-2007-4399: CRLF injection vulnerability in the xmms.bx 1.0 script for BitchX allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
  • CVE-2007-4400: CRLF injection vulnerability in the included media script in Konversation allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
  • CVE-2007-4401: Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
  • CVE-2007-4402: Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
  • CVE-2007-4403: The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
  • SA26454: XMMS-Control for XChat id3 Tag Input Validation Error
  • SA26455: xchat-xmms for XChat id3 Tag Input Validation Error
  • SA26456: Konversation Media Script id3 Tag Input Validation Error
  • SA26457: now_playing.rb for weechat id3 Tag Input Validation Error
  • SA26483: Multiple irssi Music Announcement Scripts id3 Tag Input Validation Error
  • SA26484: xmms-thing for XChat id3 Tag Input Validation Error
  • SA26485: XMMS Remote Control Script for XChat id3 Tag Input Validation Error
  • SA26486: Disrok for XChat id3 Tag Input Validation Error
  • SA26487: a2x for XChat id3 Tag Input Validation Error
  • SA26488: Another xmms-info script for XChat id3 Tag Input Validation Error
  • SA26489: xmms.bx for BitchX id3 Tag Input Validation Error
  • SA26490: xmms.pl for weechat id3 Tag Input Validation Error
  • SA26491: Advanced mIRC Integration Plugin id3 Tag Input Validation Error

Platforms Affected:

  • Colten Edwards BitchX 1.0
  • Craig Kelley xchat-xmms 0.81
  • FedoraProject Fedora Core 6
  • FlashTux WeeChat 0.1
  • FlashTux WeeChat 1.1
  • irssi irssi prior to 0.8.11
  • irssi ixmmsa.pl 0.3
  • irssi l33tmusic.pl 2.00
  • irssi mpg123.pl 0.01
  • irssi ogg123.pl 0.01
  • irssi xmms.pl 2.0
  • irssi xmms2.pl 1.1.3
  • irssi xmmsinfo.pl 1.1.1.1
  • Joe Thielen XMMS-Control 0.33
  • Konversation Konversation 1.0.1
  • mIRC mIRC 2.49
  • Peter Zelezny XChat 0.8.1 - 1.0
  • XChat a2x 0.0.1
  • XChat Another xmms-info script 1.0
  • XChat Disrok 1.0
  • XChat XMMS Remote Control Script 1.07
  • XChat xmms-thing 1.0

Reported:

Aug 12, 2007

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page

* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

About IBM Internet Security Systems

IBM Internet Security Systems is a trusted security advisor to thousands of the world's leading businesses and governments, helping to provide pre-emptive protection for networks, desktops and servers. The IBM Proventia? integrated security platform is designed to automatically protect against both known and unknown threats, helping to keep networks up and running and shield customers from online attacks before they impact business assets. IBM Internet Security Systems products and services are based on the proactive security intelligence of its X-Force? research and development team ? an unequivocal world authority in vulnerability and threat research. The IBM Internet Security Systems product line is also complemented by comprehensive Managed Security Services and Professional Security Services. For more information, visit the IBM Internet Security Systems Web site at www.iss.net or call 800-776-2362.