Vulnerabilities > CVE-2006-6811 - Reachable Assertion vulnerability in multiple products

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
kde
canonical
CWE-617
nessus
exploit available

Summary

KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue was originally reported as a buffer overflow.

Vulnerable Configurations

Part Description Count
Application
Kde
1
OS
Canonical
3

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionKsIRC 1.3.12 (PRIVMSG) Remote Buffer Overflow PoC. CVE-2006-6811. Dos exploit for linux platform
fileexploits/linux/dos/3023.c
idEDB-ID:3023
last seen2016-01-31
modified2006-12-26
platformlinux
port
published2006-12-26
reporterFederico L. Bossi Bonin
sourcehttps://www.exploit-db.com/download/3023/
titleKsIRC 1.3.12 - PRIVMSG Remote Buffer Overflow PoC
typedos

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200701-26.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200701-26 (KSirc: Denial of Service vulnerability) KSirc fails to check the size of an incoming PRIVMSG string sent from an IRC server during the connection process. Impact : A malicious IRC server could send a long PRIVMSG string to the KSirc client causing an assertion failure and the dereferencing of a null pointer, resulting in a crash. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id24311
    published2007-02-09
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24311
    titleGLSA-200701-26 : KSirc: Denial of Service vulnerability
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-409-1.NASL
    descriptionFederico L. Bossi Bonin discovered a Denial of Service vulnerability in ksirc. By sending a special response packet, a malicious IRC server could crash ksirc. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id27997
    published2007-11-10
    reporterUbuntu Security Notice (C) 2007-2019 Canonical, Inc. / NASL script (C) 2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/27997
    titleUbuntu 5.10 / 6.06 LTS / 6.10 : kdenetwork vulnerability (USN-409-1)
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2007-009.NASL
    descriptionKsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. Updated packages are patched to address this issue.
    last seen2020-06-01
    modified2020-06-02
    plugin id24625
    published2007-02-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24625
    titleMandrake Linux Security Advisory : kdenetwork (MDKSA-2007:009)

Statements

contributorMark J Cox
lastmodified2007-01-18
organizationRed Hat
statementWe do not consider a crash of a client application such as KsIRC to be a security issue.