Fixed easily exploitable 0day involving wide characters. Slightly surprised no one has triggered this yet, as exploitation involves nothing more than having Auto send a >8-byte character (, "𝄞"), via doing something like using LinkTitle.pm and putting the character into the <title> field.. This is a MAJOR security exploiit, and any user using a module where Auto would echo user-defined data should update immediately.

This commit is contained in:
Alyx committed 2011-04-13 19:58:25 -05:00
1 parent 1adcd0323b
commit bb10d54844
1 file changed
+1
+1
View File
@@ -211,6 +211,7 @@ sub ircsock {
$Auto::SOCKET{$svrname} = IO::Socket::INET->new(%conndata) or # Or error.
err(2, 'Failed to connect to server ('.$ERRNO.'): '.$svrname.' ['.$cdata->{'host'}[0].q{:}.$cdata->{'port'}[0].']', 0)
and delete $Auto::SOCKET{$svrname} and next;
binmode($Auto::SOCKET{$svrname}, ':encoding(UTF-8)');
}
}