PT-2004-2162 · Kreed · Kreed

Published

2004-12-15

·

Updated

2017-07-11

·

CVE-2004-1214

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Kreed versions 1.05 and earlier
Description: The issue allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2) message text. This can be achieved by including format specifiers in these fields.
Recommendations: For versions 1.05 and earlier, consider disabling the ability to include format specifiers in user-inputted fields such as nickname and message text until a patch is available. Restrict access to these features to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1214

Affected Products

Kreed