First published: Wed Dec 17 2003(Updated: )
xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null dereference.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XChat | =2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1000 is classified as a denial of service vulnerability due to its ability to crash xchat 2.0.6.
To fix CVE-2003-1000, upgrade to a version of xchat later than 2.0.6 that addresses this vulnerability.
CVE-2003-1000 affects xchat version 2.0.6.
The denial of service in CVE-2003-1000 is caused by a null dereference from a passive DCC request with an invalid ID number.
Yes, CVE-2003-1000 can be exploited remotely by attackers sending a specially crafted passive DCC request.