First published: Mon Mar 19 2007(Updated: )
Multiple format string vulnerabilities in comm.c in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via format string specifiers to the create_ctcp_message function using the message argument to the (1) me or (2) ctcp commands, and possibly related vectors involving the (3) whois, (4) mode, and (5) topic commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Rhapsody | =0.28b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1503 has a high severity rating due to its potential to allow remote execution of arbitrary code.
To mitigate CVE-2007-1503, update Rhapsody IRC to a version that is not vulnerable, preferably later than 0.28b.
CVE-2007-1503 specifically affects Rhapsody IRC version 0.28b.
CVE-2007-1503 enables attackers to exploit multiple format string vulnerabilities, potentially allowing for arbitrary code execution.
Yes, CVE-2007-1503 involves vulnerabilities that arise from improper handling of user input in specific command messages.