The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Irc_client | Kvirc | 3.2.0 (including) | 3.2.0 (including) |
Kvirc | Ubuntu | dapper | * |
Kvirc | Ubuntu | devel | * |
Kvirc | Ubuntu | edgy | * |
Kvirc | Ubuntu | feisty | * |