CVE-2003-0324Improper Restriction of Operations within the Bounds of a Memory Buffer in Epic4

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 23.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 9
Latest updateApr 29

Description

Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2) Statusbar capability.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/epic4< epic4 1:1.1.11.20030409-1 (bookworm)
Debianepic/epic4< 1:1.1.11.20030409-1+3
NVDepic/epic41.0.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-88jf-xx4f-mf96: Buffer overflows in EPIC IRC Client (EPIC4) 12022-04-29
OSV
CVE-2003-0324: Buffer overflows in EPIC IRC Client (EPIC4) 12003-06-09

📋Vendor Advisories

1
Debian
CVE-2003-0324: epic4 - Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC se...2003
CVE-2003-0324 — Debian Epic4 vulnerability | cvebase