CVE-2006-4127
Summary
| CVE | CVE-2006-4127 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-14 23:04:00 UTC |
| Updated | 2018-10-17 21:33:00 UTC |
| Description | Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a) cmd.user.c, (b) penalties.c, or (c) cmd.dc.c. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dconnect | Dconnect Daemon | 0.0.2 | All | All | All |
| Application | Dconnect | Dconnect Daemon | 0.0.3 | All | All | All |
| Application | Dconnect | Dconnect Daemon | 0.7.0 | All | All | All |
| Application | Dconnect | Dconnect Daemon | 0.0.2 | All | All | All |
| Application | Dconnect | Dconnect Daemon | 0.0.3 | All | All | All |
| Application | Dconnect | Dconnect Daemon | 0.7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - DConnect Daemon Multiple Vulnerabilities | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - DConnect Daemon Format String and Buffer Overflow Flaws Let Remote Users Deny Service or Execute Arbitrary Code | SECTRACK | securitytracker.com | Exploit |
| SecurityReason - Multiple vulnerabilities in DConnect Daemon 0.7.0 (CVS 30 Jul 2006) | SREASON | securityreason.com | |
| www.dc.ds.pg.gda.pl | CONFIRM | www.dc.ds.pg.gda.pl | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| DConnect Daemon | CONFIRM | www.dc.ds.pg.gda.pl | Patch |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| DConnect Daemon Multiple Format String Vulnerabilities | BID | www.securityfocus.com | Exploit, Patch |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.