CVE-2005-0226: High severity ngircd ngircd vulnerability
Published Feb 3, 2005
·Updated
Format string vulnerability in the LogResolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.
Affected Software
1 affected component
ngircd ngircd=0.8.2
Remediation
Patch Available
Patch Available
Event History
Feb 3, 2005
CVE Published
05:00 AM
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0226?
CVE-2005-0226 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2005-0226?
To fix CVE-2005-0226, upgrade ngIRCd to version 0.8.3 or later, which addresses this vulnerability.
3
What software is affected by CVE-2005-0226?
CVE-2005-0226 affects ngIRCd versions 0.8.2 and earlier when compiled with specific configurations.
4
What is the nature of the vulnerability in CVE-2005-0226?
CVE-2005-0226 is a format string vulnerability that allows remote attackers to execute arbitrary code.
5
What conditions must be met for CVE-2005-0226 to be exploitable?
CVE-2005-0226 is exploitable when ngIRCd is configured to use IDENT, logging to SYSLOG, and with DEBUG enabled.