CVE-2009-20007

Talkative IRC v0.4.4.16 - Buffer Overflow

Title source: llm

Description

Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execution in the context of the vulnerable process. This vulnerability is exploitable remotely and does not require authentication.

Exploits (3)

metasploit WORKING POC NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/talkative_response.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16459
exploitdb WORKING POC VERIFIED
by LiquidWorm · perlremotewindows
https://www.exploit-db.com/exploits/8227

Scores

EPSS 0.5975
EPSS Percentile 98.2%

Classification

CWE
CWE-121
Status draft

Timeline

Published Sep 16, 2025
Tracked Since Feb 18, 2026