CVE Vulnerabilities

CVE-2007-1503

Published: Mar 19, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple format string vulnerabilities in comm.c in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via format string specifiers to the create_ctcp_message function using the message argument to the (1) me or (2) ctcp commands, and possibly related vectors involving the (3) whois, (4) mode, and (5) topic commands.

Affected Software

NameVendorStart VersionEnd Version
Rhapsody_ircRhapsody_irc0.28b (including)0.28b (including)
RhapsodyUbuntudapper*
RhapsodyUbuntuedgy*
RhapsodyUbuntufeisty*
RhapsodyUbuntugutsy*

References