Title: mIRC Scripting ASCTime Buffer Overflow Vulnerability
Severity: HIGH
Description:
mIRC is a chat client for the IRC protocol, designed for Microsoft Windows based operating systems. mIRC includes support for a scripting language.
A buffer overflow vulnerability has been reported in the $asctime identifier, a function in the mIRC scripting language. If an oversized format specifier is passed to this function, process memory will be corrupted. It has been reported possible to exploit this vulnerability to execute arbitrary code with the privileges of the user running mIRC.
Exploitation will rely on a script passing untrusted output to the vulnerable function. Reportedly, default scripts included with mIRC do not use the $asctime function in a manner which allows exploitation. It is possible, however, that third party scripts may provide possibilities for attackers.
Affected Products:
- Khaled Mardam-Bey mIRC 6.0.0
- Khaled Mardam-Bey mIRC 6.0.0 1
- Khaled Mardam-Bey mIRC 6.0.0 2
References:
- mIRC: mIRC Homepage
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.