ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) certain other arguments that represent groups of IP addresses, then monitoring CTCP ping replies.
Link | Tags |
---|---|
http://securityreason.com/securityalert/3031 | third party advisory |
http://www.securityfocus.com/archive/1/476285/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35997 | vdb entry |
http://www.securityfocus.com/bid/25285 | vdb entry exploit |