Title: mIRC Scripting ASCTime Buffer Overflow Vulnerability
Severity: MODERATE
Description:
mIRC is a chat client for the IRC protocol, designed for Microsoft Windows based operating systems. mIRC includes support for a scripting language.
A buffer overflow vulnerability has been reported in the $asctime identifier, a function in the mIRC scripting language. If an oversized format specifier is passed to this function, process memory will be corrupted. It has been reported possible to exploit this vulnerability to execute arbitrary code with the privileges of the user running mIRC.
Exploitation will rely on a script passing untrusted output to the vulnerable function. Reportedly, default scripts included with mIRC do not use the $asctime function in a manner which allows exploitation. It is possible, however, that third party scripts may provide possibilities for attackers.
Affected Products:
- Khaled Mardam-Bey mIRC 6.0.0
- Khaled Mardam-Bey mIRC 6.0.01
- Khaled Mardam-Bey mIRC 6.0.02
References:
- mIRC: mIRC Homepage
