Vulnerability Name: | CVE-2007-2807 (CCN-34407) | ||||||||||||||||||||||||||||
Assigned: | 2007-04-19 | ||||||||||||||||||||||||||||
Published: | 2007-04-19 | ||||||||||||||||||||||||||||
Updated: | 2009-07-10 | ||||||||||||||||||||||||||||
Summary: | Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 6.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:U/RC:UR)
4.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:F/RL:U/RC:UR)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: CONFIRM Type: UNKNOWN http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=427157 Source: MITRE Type: CNA CVE-2007-2807 Source: OSVDB Type: UNKNOWN 36237 Source: CCN Type: SA25276 Eggdrop Server Module Private Message Processing Buffer Overflow Source: SECUNIA Type: Vendor Advisory 25276 Source: SECUNIA Type: UNKNOWN 26727 Source: SECUNIA Type: UNKNOWN 26826 Source: SECUNIA Type: UNKNOWN 27989 Source: SECUNIA Type: UNKNOWN 28347 Source: SECUNIA Type: UNKNOWN 35690 Source: GENTOO Type: UNKNOWN GLSA-200709-07 Source: CCN Type: SECTRACK ID: 1018700 Eggdrop Stack Overflow in `servrmsg.c` Lets Remote Servers Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1018700 Source: DEBIAN Type: UNKNOWN DSA-1448 Source: DEBIAN Type: UNKNOWN DSA-1826 Source: DEBIAN Type: DSA-1448 eggdrop -- buffer overflow Source: DEBIAN Type: DSA-1826 eggdrop -- several vulnerabilities Source: CCN Type: Egghead Web site Eggheads.org - Main Index Source: CCN Type: Eggheads Bugzilla Bug 462 multiple buffer overflows in server module Source: MISC Type: Exploit http://www.eggheads.org/bugzilla/show_bug.cgi?id=462 Source: CCN Type: GLSA-200709-07 Eggdrop: Buffer overflow Source: MANDRIVA Type: UNKNOWN MDKSA-2007:175 Source: CCN Type: OSVDB ID: 36237 Eggdrop Server Module servrmsg.c Private Message Handling Overflow Source: CCN Type: OSVDB ID: 54460 Eggdrop /mod/server.mod/servrmsg.c Private Message Handling DoS Source: BID Type: UNKNOWN 24070 Source: CCN Type: BID-24070 Eggdrop Server Module Message Handling Remote Buffer Overflow Vulnerability Source: XF Type: UNKNOWN eggdrop-server-module-bo(34407) Source: FEDORA Type: UNKNOWN FEDORA-2007-4305 Source: FEDORA Type: UNKNOWN FEDORA-2007-4325 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |