vendor:
IRCIT
by:
7.5
CVSS
HIGH
Remote Buffer Overflow
CWE
Product Name: IRCIT
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux, Unix
IRCIT Remote Buffer Overflow Vulnerability
The IRCIT client is vulnerable to a remote buffer overflow vulnerability. When an INVITE message is received, the supplied from user data is copied into a fixed buffer of length MAXHOSTLEN. A maliciously formatted message can overflow this buffer and execute arbitrary code.
Mitigation:
Apply patches or updates provided by the vendor. Avoid accepting INVITE messages from untrusted sources.