CVE-2007-0344

Colloquy < 2.1 - Remote Code Execution via Format String in INVITE Channel Name

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-0344. PoCs published by MoAB.

AI-analyzed exploit summary This exploit targets a format string vulnerability in Colloquy IRC client by sending maliciously crafted INVITE messages to trigger arbitrary code execution. It connects to an IRC server, joins a channel with a format string payload, and invites users to exploit the vulnerability.

Description

Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.

Exploits (1)

exploitdb WORKING POC VERIFIED
by MoAB · rubydososx
https://www.exploit-db.com/exploits/3139

This exploit targets a format string vulnerability in Colloquy IRC client by sending maliciously crafted INVITE messages to trigger arbitrary code execution. It connects to an IRC server, joins a channel with a format string payload, and invites users to exploit the vulnerability.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Colloquy IRC client (version not specified)
No auth needed
Prerequisites: Network access to the target IRC server · Victim must be using a vulnerable version of Colloquy IRC client
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22086
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0238
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/32688
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3139
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23801

Scores

EPSS 0.0656
EPSS Percentile 92.9%

Details

CWE
CWE-134
Status published
Products (1)
colloquy/colloquy < 2.1
Published Jan 18, 2007
Tracked Since Feb 18, 2026