KVIrc URI Handler Remote Command Execution Vulnerability
BID:24652
Info
KVIrc URI Handler Remote Command Execution Vulnerability
| Bugtraq ID: | 24652 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2951 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2007 12:00AM |
| Updated: | Sep 13 2007 10:40PM |
| Credit: | Stefan Cornelius of Secunia Research is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 KVIrc KVirc 3.2.5 KVIrc KVirc 3.2 Gentoo Linux |
| Not Vulnerable: | |
Discussion
KVIrc URI Handler Remote Command Execution Vulnerability
KVIrc is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue would allow an attacker to execute arbitrary commands within the context of the affected application.
KVIrc is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue would allow an attacker to execute arbitrary commands within the context of the affected application.
Exploit / POC
KVIrc URI Handler Remote Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
KVIrc URI Handler Remote Command Execution Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
KVIrc URI Handler Remote Command Execution Vulnerability
References:
References:
- KVirc Homepage (KVirc)
- Secunia Research: KVIrc irc:// URI Handler Command Execution Vulnerability (Secunia Research)
- Secunia Research: KVIrc irc:// URI Handler Command Execution Vulnerability (Secunia Research)
- Changeset 630 (KVIrc)