Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2000-0594

6 documents6 sources
Severity
5.0MEDIUM
EPSS
10.8%
top 6.64%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 4
Latest updateApr 30

Description

BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

Also affects: Freebsd 3.5, 4.0

🔴Vulnerability Details

2
GHSA
GHSA-gghx-4gcj-rpw8: BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a2022-04-30
CVEList
CVE-2000-0594: BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a2000-10-13

💥Exploits & PoCs

1
Exploit-DB
BitchX IRC Client 75p1/75p3/1.0 c16 - '/INVITE' Format String2000-07-05

📋Vendor Advisories

1
Red Hat
security flaw2000-07-05

💬Community

1
Bugzilla
CVE-2000-0594 security flaw2018-08-16