OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: XChat 2.8.4-1 - Multiple Vulnerabilities

From: fabio (ctrlaltcalibero.it)
Date: Fri Mar 28 2008 - 13:13:36 CDT


1) Password disclosure
What priviledges on the system do you need to read that process memory?
With such priviledges, why don't you read the data directly from the
config file?
2) Local Dos
Is the build unoficial/unsupported from the XChat team? Does the same
bug exists in the official builds?
You talk about a local dos.. how can a user access the tray icon of
another user to trigger the crash?

Please explain

CtrlAltCa