CVE-2007-3360

hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bitchx:bitchx:1.1-final:*:*:*:*:*:*:*

History

21 Nov 2024, 00:33

Type Values Removed Values Added
References () http://osvdb.org/37479 - () http://osvdb.org/37479 -
References () http://secunia.com/advisories/25759 - Vendor Advisory () http://secunia.com/advisories/25759 - Vendor Advisory
References () http://secunia.com/advisories/34870 - () http://secunia.com/advisories/34870 -
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.285737 - () http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.285737 -
References () http://www.securityfocus.com/bid/24579 - () http://www.securityfocus.com/bid/24579 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34969 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/34969 -
References () https://www.exploit-db.com/exploits/4087 - () https://www.exploit-db.com/exploits/4087 -

Information

Published : 2007-06-22 18:30

Updated : 2024-11-21 00:33


NVD link : CVE-2007-3360

Mitre link : CVE-2007-3360

CVE.ORG link : CVE-2007-3360


JSON object : View

Products Affected

bitchx

  • bitchx