CVE-2000-0787: High severity Xchat xchat vulnerability
Published Oct 13, 2000
·Updated
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.
Affected Software
11 affected components
Xchat xchat=1.2.1
Xchat xchat=1.3.10
Xchat xchat=1.4
Xchat xchat=1.5.xdev
Xchat xchat=1.5.6
Xchat xchat=1.3.13
Xchat xchat=1.3.9
Xchat xchat=1.3.12
Xchat xchat=1.4.1
Xchat xchat=1.4.2
Xchat xchat=1.3.11
Event History
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0787?
CVE-2000-0787 has a medium severity rating as it allows remote attackers to execute arbitrary commands.
2
How do I fix CVE-2000-0787?
To fix CVE-2000-0787, users should upgrade to a version of XChat later than 1.4.2.
3
Which versions of the XChat client are affected by CVE-2000-0787?
CVE-2000-0787 affects XChat client versions 1.4.2 and earlier.
4
What type of attack is enabled by CVE-2000-0787?
CVE-2000-0787 enables a remote command execution attack through encoded shell metacharacters in URLs.
5
Is there a workaround for CVE-2000-0787 if I can't upgrade XChat?
A temporary workaround for CVE-2000-0787 involves disabling URL handling in the XChat client, but upgrading is strongly recommended.