The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, contains an externally introduced backdoor that e-mails sensitive information (hostnames, usernames, and shell history) to a fixed address.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/483350/100/0/threaded | mailing list |
http://secunia.com/advisories/27556 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/26372 | vdb entry |
http://osvdb.org/42073 | vdb entry |