DSA-306Vendor advisory
http://www.debian.org/security/2003/dsa-306 CVE-2003-0328
Epic 1.0.1/1.0.x - CTCP Nickname Server Message Buffer Overrun
Record summary
CVE-2003-0328 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEpic 1.0.1/1.0.x - CTCP Nickname Server Message Buffer OverrunExploitDB exploitby Li0n7Not analyzed1 file
References
4DSA-399Vendor advisory
http://www.debian.org/security/2003/dsa-399 RHSA-2003:342Vendor advisory
http://www.redhat.com/support/errata/RHSA-2003-342.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0328