PT-2004-3444 · Ignition · Ignitionserver

Keith Gable

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2553

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions The Ignition Project ignitionServer versions 0.1.2 through 0.1.2-R2
Description The issue allows remote authenticated users with local IRC operator privileges to obtain global IRC operator privileges. This is achieved by using the unofficial umode command with the +ORD argument.
Recommendations For versions 0.1.2 through 0.1.2-R2, consider restricting access to the umode command or removing the +ORD argument functionality to prevent exploitation until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2553

Affected Products

Ignitionserver