Vulnerability disclosure: possible remote crash in ADCH++
February 15, 2025 Leave a comment
A fix that prevents the latest and older versions of ADCH++ to be remote crashed in a rather trivial way has been committed to the official repository.
The vulnerability allows a malicious remote user to terminate any ADCH++ hub service by sending a specially crafted INF command with I4 or I6 flags that contain an invalid or malformed IP address.
Hub owners running ADCH++ on *nix operating systems are recommended to update and recompile their hub software as soon as possible to be protected from a possible denial of service attack. If you run ADCH++ on Windows and want to be safe before the next release then please get an updated binary from our builds server or visit the development hub at adcs://hub.dcbase.org:16591 for more information.