7.5
CVSSv2

CVE-2003-0328

Published: 09/06/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.

Vulnerable Product Search on Vulmon Subscribe to Product

epic epic4 pre2.002

epic epic4 pre2.003

Exploits

source: wwwsecurityfocuscom/bid/8999/info A remotely exploitable buffer overrun has been reported in Epic This issue may reportedly be exploited by a malicious server that supplies an overly long nickname in a CTCP messages, potentially allowing for execution of arbitrary code in the context of the client user It may be also be possible ...