PT-2007-2893 · Rhapsody · Rhapsody Irc
Starcadi
·
Published
2007-03-19
·
Updated
2018-10-16
·
CVE-2007-1502
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Rhapsody IRC version 0.28b
Description
The issue allows remote attackers to execute arbitrary code due to multiple buffer overflows. This can be achieved through various means, including a long command, a long server argument to the connect or server commands, a long nick argument to the nick command, or a long nick or message argument to the ctcp, chat, notice, message (msg), or query commands.
Recommendations
For Rhapsody IRC version 0.28b, consider disabling the affected commands (connect, server, nick, ctcp, chat, notice, message, query) until a patch is available to prevent exploitation. Restrict access to these commands to minimize the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rhapsody Irc