Executive brief
HexChat is a popular open-source IRC (Internet Relay Chat) client used for real-time communication. A vulnerability in how the application handles messages from chat servers allows a malicious or compromised server to crash the user's software. This can lead to a denial of service, preventing users from communicating and potentially causing the loss of unsaved chat logs or session data.
Technical details
A stack-based buffer overflow exists in the 'inbound_cap_ls' function within 'common/inbound.c' of HexChat versions 2.10.2 and 2.11.0. The vulnerability occurs when the client processes a CAP LS message from an IRC server to negotiate extensions. The application attempts to construct a CAP REQ response string in a fixed-size 256-byte buffer; while this buffer is sufficient for all unique standard options, it can be overflowed if a malicious server sends a large number of repeated options. An attacker controlling a remote IRC server can exploit this to cause a segmentation fault or access violation, resulting in a denial of service. Public exploit code (PoC) is available.
Affected products
- HexChat Project HexChat 2.10.2, 2.11.0
Timeline
- 2016-02-07: disclosed: Vulnerability discovered and exploit authored by PizzaHatHacker
- 2016-04-04: other: Exploit published to Exploit-DB
- 2017-01-18: advisory: NVD published the CVE record