vendor:
Behamut IRCd
by:
Dinos nagash
7.5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: Behamut IRCd
Affected Version From: Behamut IRCd <= 1.4.35
Affected Version To: Behamut IRCd <= 1.4.35
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003
Behamut IRCd Remote Format String Vulnerability
Behamut IRCd has been reported prone to remotely exploitable format string vulnerability. The issue presents itself when Behamut is compiled with DEBUGMODE defined. Reportedly a remote attacker may send malicious format specifiers to trigger an error. By passing specially crafted format specifiers through the IRC session, a remote attacker could potentially corrupt process memory and may have the ability to execute arbitrary code with the privileges of the affected daemon. It should be noted that IRC daemons that are derived from the Behamut source have also been reported vulnerable.
Mitigation:
Disable DEBUGMODE in Behamut IRCd