9.3
CVSSv2

CVE-2007-2951

Published: 26/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote malicious users to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.

Vulnerable Product Search on Vulmon Subscribe to Product

kvirc irc client 3.2.0

Vendor Advisories

Debian Bug report logs - #434419 kvirc: Arbitrary command execution with irc:// and irc6:// URIs (CVE-2007-2951) Package: kvirc; Maintainer for kvirc is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Source for kvirc is src:kvirc (PTS, buildd, popcon) Reported by: Edgar Ibsen <edgaribsen2@yahoocom> ...