CVE Vulnerabilities

CVE-2010-2785

Published: Aug 02, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle (backslash) characters, which allows remote authenticated users to execute arbitrary CTCP commands via vectors involving r and 40 sequences, a different vulnerability than CVE-2010-2451 and CVE-2010-2452.

Affected Software

NameVendorStart VersionEnd Version
KvircKvirc3.0.0 (including)3.0.0 (including)
KvircKvirc3.0.0-beta1 (including)3.0.0-beta1 (including)
KvircKvirc3.0.0-beta2 (including)3.0.0-beta2 (including)
KvircKvirc3.0.1 (including)3.0.1 (including)
KvircKvirc3.4.0 (including)3.4.0 (including)
KvircKvirc3.4.2 (including)3.4.2 (including)
KvircKvirc3.4.2-rc1 (including)3.4.2-rc1 (including)
KvircKvirc4.0.0 (including)4.0.0 (including)
KvircKvirc4.0.2 (including)4.0.2 (including)
KvircUbuntudapper*
KvircUbuntuhardy*
KvircUbuntujaunty*
KvircUbuntukarmic*
KvircUbuntulucid*
KvircUbuntuupstream*

References