First published: Fri Dec 31 2004(Updated: )
The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BNC IRC | =2.2.4 | |
BNC IRC | =2.4.6 | |
BNC IRC | =2.4.8 | |
BNC IRC | =2.6 | |
BNC IRC | =2.6.2 | |
BNC IRC | =2.8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1482 is considered a medium severity vulnerability that could allow remote authentication bypass.
To fix CVE-2004-1482, upgrade BNC to version 2.8.9 or later, which addresses the vulnerability.
CVE-2004-1482 affects BNC versions 2.2.4, 2.4.6, 2.4.8, 2.6, 2.6.2, and 2.8.8.
CVE-2004-1482 enables remote attackers to bypass authentication and potentially access arbitrary scripts.
Yes, the permanent solution for CVE-2004-1482 is to upgrade to versions of BNC that are not vulnerable, specifically version 2.8.9 or newer.