Description
Multiple buffer overflows in client.c in CGI:IRC (CGIIRC) before 0.5.8 might allow remote attackers to execute arbitrary code via (1) cookies or (2) the query string.
Affected products
- cgiirc / cgiirc0.5.4 – 0.5.4
- cgiirc / cgiirc0.5.7 – 0.5.7
References
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/1607
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/26173
- MISChttp://cvs.cgiirc.org/chngview?cn=283
- VENDOR_ADVISORYhttp://secunia.com/advisories/19985
- MISChttp://cvs.cgiirc.org/chngview?cn=263
- VENDOR_ADVISORYhttp://secunia.com/advisories/19922
- MISChttp://cvs.cgiirc.org/timeline?d=300&e=2006-Apr-30&c=2&px=&s=0&dm=1&x=1&m=1
- MISChttp://www.securityfocus.com/bid/17799
- VENDOR_ADVISORYhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365680
- VENDOR_ADVISORYhttp://www.debian.org/security/2006/dsa-1052