hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands.
Link | Tags |
---|---|
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.285737 | vendor advisory |
http://secunia.com/advisories/34870 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34969 | vdb entry |
https://www.exploit-db.com/exploits/4087 | exploit |
http://www.securityfocus.com/bid/24579 | vdb entry |
http://secunia.com/advisories/25759 | third party advisory vendor advisory |
http://osvdb.org/37479 | vdb entry |