Vulnerability Name: | CVE-2006-6811 (CCN-31134) | ||||||||
Assigned: | 2006-12-26 | ||||||||
Published: | 2006-12-26 | ||||||||
Updated: | 2018-10-17 | ||||||||
Summary: | KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. Note: this issue was originally reported as a buffer overflow. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-6811 Source: OSVDB Type: UNKNOWN 33443 Source: CCN Type: Debian - KDE IRC client Web page Ksirc package Source: GENTOO Type: UNKNOWN GLSA-200701-26 Source: CCN Type: SECTRACK ID: 1017453 KSirc Client PRIVMSG Buffer Overflow May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1017453 Source: MISC Type: UNKNOWN http://www.addict3d.org/index.php?page=viewarticle&trace=0&type=security&ID=8468 Source: CCN Type: GLSA-200701-26 KSirc: Denial of Service vulnerability Source: CCN Type: KDE Security Advisory 20070109-1 ksirc denial of service vulnerability Source: CONFIRM Type: UNKNOWN http://www.kde.org/info/security/advisory-20070109-1.txt Source: MANDRIVA Type: UNKNOWN MDKSA-2007:009 Source: CCN Type: OSVDB ID: 33443 KDE KsIRC PRIVMSG String Remote DoS Source: BUGTRAQ Type: UNKNOWN 20070109 [KDE Security Advisory] ksirc Denial of Service vulnerability Source: BID Type: Exploit 21790 Source: CCN Type: BID-21790 KSirc IRC Client Remote PRIVMSG Denial of Service Vulnerability Source: CCN Type: TLSA-2007-15 KsIRC denial of service vulnerability Source: CCN Type: USN-409-1 ksirc vulnerability Source: UBUNTU Type: UNKNOWN USN-409-1 Source: VUPEN Type: UNKNOWN ADV-2006-5199 Source: XF Type: UNKNOWN ksirc-privmsg-bo(31134) Source: XF Type: UNKNOWN ksirc-privmsg-bo(31134) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-922 Source: EXPLOIT-DB Type: UNKNOWN 3023 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |