CVE Vulnerabilities

CVE-2007-1503

Published: Mar 19, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Multiple format string vulnerabilities in comm.c in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via format string specifiers to the create_ctcp_message function using the message argument to the (1) me or (2) ctcp commands, and possibly related vectors involving the (3) whois, (4) mode, and (5) topic commands.

Affected Software

Name Vendor Start Version End Version
Rhapsody_irc Rhapsody_irc 0.28b (including) 0.28b (including)
Rhapsody Ubuntu dapper *
Rhapsody Ubuntu edgy *
Rhapsody Ubuntu feisty *
Rhapsody Ubuntu gutsy *

References