5
CVSSv2

CVE-2000-0594

Published: 04/07/2000 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

BitchX IRC client does not properly cleanse an untrusted format string, which allows remote malicious users to cause a denial of service via an invite to a channel whose name includes special formatting characters.

Vulnerable Product Search on Vulmon Subscribe to Product

caldera openlinux ebuilder 2.3

caldera openlinux desktop 2.3

freebsd freebsd 3.5

freebsd freebsd 4.0

mandrakesoft mandrake linux 2007

caldera openlinux edesktop 2.4

caldera openlinux eserver 2.3

Exploits

source: wwwsecurityfocuscom/bid/1436/info BitchX IRC clients, versions 75 up to and including 10c16, are vulnerable to a Denial of Service and possible remote execution of code By /invite-ing someone to a channel name containing formatting characters (%s, %n, etc) an IRC user can cause the targetted user's BitchX client to seg-fault Th ...