4.3
CVSSv2

CVE-2006-6811

Published: 29/12/2006 Updated: 08/02/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

KsIRC 1.3.12 allows remote malicious users to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue was originally reported as a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

kde ksirc 1.3.12

canonical ubuntu linux 6.10

canonical ubuntu linux 5.10

canonical ubuntu linux 6.06

Vendor Advisories

Federico L Bossi Bonin discovered a Denial of Service vulnerability in ksirc By sending a special response packet, a malicious IRC server could crash ksirc ...

Exploits

// KSirc 1312 - PRIVMSG remote Buffer Overflow // PoC // // Federico L Bossi Bonin // fbossi@globalstcomar // wwwGlobalSTcomar // #0 0xb7ea8792 in KSircIOController::stdout_read () from /usr/kde/35/lib/libkdeinit_ksircso // #1 0xb7ea78c8 in KSircIOController::qt_invoke () from /usr/kde/35/lib/libkdeinit_ksircso // #2 0xb6fedba4 in ...