PT-1999-1085 · Mirc · Mirc

Published

1999-01-01

·

Updated

2022-08-17

·

CVE-1999-0399

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mirc version 5.5
Description The issue concerns a problem with the DCC server command in the Mirc client, where it fails to properly filter characters from file names. This allows remote attackers to potentially place a malicious file in a different location, which could lead to the execution of commands.
Recommendations For Mirc version 5.5, consider restricting the use of the DCC server command until a proper fix is available, to minimize the risk of malicious file placement and potential command execution.

Fix

Related Identifiers

CVE-1999-0399

Affected Products

Mirc