CVE Vulnerabilities

CVE-2007-2951

Published: Jun 26, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.

Affected Software

Name Vendor Start Version End Version
Irc_client Kvirc 3.2.0 (including) 3.2.0 (including)
Kvirc Ubuntu dapper *
Kvirc Ubuntu devel *
Kvirc Ubuntu edgy *
Kvirc Ubuntu feisty *

References