PT-1999-1085 · Mirc · Mirc
Published
1999-01-01
·
Updated
2022-08-17
·
CVE-1999-0399
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mirc version 5.5
Description
The issue concerns a problem with the DCC server command in the Mirc client, where it fails to properly filter characters from file names. This allows remote attackers to potentially place a malicious file in a different location, which could lead to the execution of commands.
Recommendations
For Mirc version 5.5, consider restricting the use of the DCC server command until a proper fix is available, to minimize the risk of malicious file placement and potential command execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mirc