CVE-2005-4681
Summary
| CVE | CVE-2005-4681 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the DCC Get Folder Dialog. NOTE: this issue has been disputed by the vendor, saying "as far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC." It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Khaled Mardam-bey | Mirc | 5.91 | All | All | All |
| Application | Khaled Mardam-bey | Mirc | 6.03 | All | All | All |
| Application | Khaled Mardam-bey | Mirc | 6.12 | All | All | All |
| Application | Khaled Mardam-bey | Mirc | 6.16 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Files ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | www.packetstormsecurity.org | Exploit |
| Certificados SSL y soluciones para empresas y pymes | Redalia | af854a3a-2127-422b-91ae-364da2661108 | www.shellsec.net | |
| trout.snt.utwente.nl/ubbthreads/showflat.php | af854a3a-2127-422b-91ae-364da2661108 | trout.snt.utwente.nl | |
| www.osvdb.org/24116 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Bugtraq: mIRC buffer overflow | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.