PT-2002-1024 · Epic4 · Light
Published
2002-09-24
·
Updated
2008-09-10
·
CVE-2002-0984
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Light versions 2.7.x through 2.7.29
Light versions 2.8.x through 2.8pre9
Description
The issue allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC4 code. Multiple vulnerabilities in the epic4-script-light package may lead to disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations
For Light versions 2.7.x through 2.7.29, update to version 2.7.30p5 or later.
For Light versions 2.8.x through 2.8pre9, update to version 2.8pre10 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Light