Vulnerability Development mailing list archives
Re: mirc32 6.0x crash when resolving dns.
From: "Roland Postle" <mail () blazde co uk>
Date: Wed, 28 May 2003 02:41:25 +0100
On Mon, 26 May 2003 23:22:37 +0200, aT4r InsaN3 wrote:
every time i tried to resolve a few ips mirc32 dies. the problem seems to be in the WSAAsyncGetHostByName() call. i have tested this feature in both mirc 6.01 and 6.03 in diferent computers.
Interestingly the bug seems to be in WS2_32.DLL itself. mIRC does a WSAAsyncGetHostByAddr() call which causes a new thread to be spawned which performs the usual gethostbyaddr() call. The returned HOSTENTcontains a NULL h_name field (as apposed to a pointer to an empty string). I can't tell if that's correct behaviour when there's no reverse lookup, but it's also interesting to note that reverse DNS lookups on the IP addresses you posted seem to fall into a loop. After performing the lookup CopyHostentToBuffer is called to copy the HOSTENT structure so it can notify the appropriate windows of the lookup's completion. BytesInHostent is called to count the number of bytes in the HOSTENT, but it trips on the NULL pointer as it tries to count how long the h_name field is. My guess: Vulnerable to NULL pointer dereference: Anything that calls WSAAsyncGetHostByAddr. (Btw, the bug appears to be WSAAsyncGetHostByName in windbg because you only have the exported symbol names loaded) Confirmed in WS2_32.DLL version 5.1.2600.0 (xpclient.010817-1148), XP SP1, mIRC 6.03. - Blazde
Current thread:
- mirc32 6.0x crash when resolving dns. aT4r InsaN3 (May 27)
- Re: mirc32 6.0x crash when resolving dns. Davide Del Vecchio (May 27)
- RE: mirc32 6.0x crash when resolving dns. Christopher Canova (May 28)
- Re[2]: mirc32 6.0x crash when resolving dns. 3APA3A (May 28)
- Re: mirc32 6.0x crash when resolving dns. Peter Pentchev (May 30)
- Re[2]: mirc32 6.0x crash when resolving dns. 3APA3A (May 30)
- Re: mirc32 6.0x crash when resolving dns. Davide Del Vecchio (May 27)
- Re: mirc32 6.0x crash when resolving dns. Bram Matthys (Syzop) (May 27)
- Re: mirc32 6.0x crash when resolving dns. at4r ins4n3 (May 28)
- Re: mirc32 6.0x crash when resolving dns. Roland Postle (May 28)