Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hv84-7vcq-ccgm

Опубликовано: 16 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execution in the context of the vulnerable process. This vulnerability is exploitable remotely and does not require authentication.

Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execution in the context of the vulnerable process. This vulnerability is exploitable remotely and does not require authentication.

EPSS

Процентиль: 99%
0.68469
Средний

9.3 Critical

CVSS4

Дефекты

CWE-121

Связанные уязвимости

nvd
5 месяцев назад

Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execution in the context of the vulnerable process. This vulnerability is exploitable remotely and does not require authentication.

EPSS

Процентиль: 99%
0.68469
Средний

9.3 Critical

CVSS4

Дефекты

CWE-121