PT-2002-1024 · Epic4 · Light

Published

2002-09-24

·

Updated

2008-09-10

·

CVE-2002-0984

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Light versions 2.7.x through 2.7.29 Light versions 2.8.x through 2.8pre9
Description The issue allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC4 code. Multiple vulnerabilities in the epic4-script-light package may lead to disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For Light versions 2.7.x through 2.7.29, update to version 2.7.30p5 or later. For Light versions 2.8.x through 2.8pre9, update to version 2.8pre10 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03470
CVE-2002-0984
DSA-156

Affected Products

Light