7.5
CVSSv2

CVE-2005-0226

Published: 03/02/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and previous versions, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote malicious users to execute arbitrary code.

Vulnerable Product Search on Vulmon Subscribe to Product

ngircd ngircd 0.8.2

Exploits

/* ngircd_fsexpc * * ngIRCd <= 082 remote format string exploit * * Note: * To obtain a successful exploitation, we need that * ngIRCd has been compiled with IDENT, logging to * SYSLOG and DEBUG enabled * * Original Reference: * wwwnosystemcomar/advisories/advisory-11txt * * root@servidor:/home/coki/audit# /ngircd_fsexp * * ngIR ...