Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Gentoo GLSA 202310-01 Alert: KVIrc Security Vulnerability Exploitation Risk

gentoo
Calendar Grey September 13, 2007
Scroller Gentoo
Critical exploit found in KVIrc necessitates swift update for those using Gentoo. Ensure protection by upgrading now.
A vulnerability has been discovered in KVIrc, allowing for the remote execution of arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200709-02 https://security.gentoo.org/ Severity: Normal Title: KVIrc: Remote arbitrary code execution Date: September 13, 2007 Bugs: #183174 ID: 200709-02

Synopsis ======= A vulnerability has been discovered in KVIrc, allowing for the remote execution of arbitrary code.
Background ========= KVIrc is a free portable IRC client based on Qt.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/kvirc < 3.2.6_pre20070714 >= 3.2.6_pre20070714
========== Stefan Cornelius from Secunia Research discovered that the "parseIrcUrl()" function in file src/kvirc/kernel/kvi_ircurl.cpp does not properly sanitise parts of the URI when building the comma...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround