The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Irc_client | Kvirc | 3.2.0 (including) | 3.2.0 (including) |
| Kvirc | Ubuntu | dapper | * |
| Kvirc | Ubuntu | devel | * |
| Kvirc | Ubuntu | edgy | * |
| Kvirc | Ubuntu | feisty | * |