hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands.
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/37479 - | |
References | () http://secunia.com/advisories/25759 - Vendor Advisory | |
References | () http://secunia.com/advisories/34870 - | |
References | () http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.285737 - | |
References | () http://www.securityfocus.com/bid/24579 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34969 - | |
References | () https://www.exploit-db.com/exploits/4087 - |
Information
Published : 2007-06-22 18:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3360
Mitre link : CVE-2007-3360
CVE.ORG link : CVE-2007-3360
JSON object : View
Products Affected
bitchx
- bitchx
CWE