Multiple format string vulnerabilities in the DCC functionality in KVIrc 3.4 and 4.0 have unspecified impact and remote attack vectors.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Kvirc | Kvirc | 3.4.0 (including) | 3.4.0 (including) |
| Kvirc | Kvirc | 4.0 (including) | 4.0 (including) |
| Kvirc | Ubuntu | jaunty | * |
| Kvirc | Ubuntu | karmic | * |
| Kvirc | Ubuntu | lucid | * |