Vulnerability Development mailing list archives

Re: mIRC Buffer Overflow


From: Blue Boar <BlueBoar () thievco com>
Date: Sun, 03 Feb 2002 14:07:15 -0800

Krish Ahya wrote:

Why would you release an exploit for this hole if currently there are no
security patches for it? Do you know how many people run mIRC? Most of which
know nothing about even how they got online! My prediction is that several
machines are going to get compromised due to this.

Did you read the page he referenced, where he indicates that he 
contacted the vendor in October, and they declined to make any changes?
http://www.uuuppz.com/research/adv-001-mirc.htm

                                        BB


Current thread: