20050203 ngIRCd <= v0.8.2 Format String Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=110746413108183&w=2 CVE-2005-0226
ngIRCd 0.8.2 - Remote Format String
Record summary
CVE-2005-0226 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBngIRCd 0.8.2 - Remote Format StringExploitDB exploitby CoKiNot analyzed1 file
References
514114Third-party advisory
http://secunia.com/advisories/14114 nosystem.com.ar
http://www.nosystem.com.ar/advisories/advisory-11.txt 12434vdb entry
http://www.securityfocus.com/bid/12434 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0226