Junglewise Threat Intelligence

CVE-2016-2233: HexChat stack buffer overflow in inbound_cap_ls function

CVE-2016-2233 · Severity: high · CVSS 7.5 · Published 2017-01-18

Executive brief

HexChat is a popular open-source IRC (Internet Relay Chat) client used for real-time communication. A vulnerability in how the application handles messages from chat servers allows a malicious or compromised server to crash the user's software. This can lead to a denial of service, preventing users from communicating and potentially causing the loss of unsaved chat logs or session data.

Technical details

A stack-based buffer overflow exists in the 'inbound_cap_ls' function within 'common/inbound.c' of HexChat versions 2.10.2 and 2.11.0. The vulnerability occurs when the client processes a CAP LS message from an IRC server to negotiate extensions. The application attempts to construct a CAP REQ response string in a fixed-size 256-byte buffer; while this buffer is sufficient for all unique standard options, it can be overflowed if a malicious server sends a large number of repeated options. An attacker controlling a remote IRC server can exploit this to cause a segmentation fault or access violation, resulting in a denial of service. Public exploit code (PoC) is available.

Affected products

  • HexChat Project HexChat 2.10.2, 2.11.0

Timeline

  • 2016-02-07: disclosed: Vulnerability discovered and exploit authored by PizzaHatHacker
  • 2016-04-04: other: Exploit published to Exploit-DB
  • 2017-01-18: advisory: NVD published the CVE record

References

Related threats