First published: Sat Nov 10 2007(Updated: )
The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, contains an externally introduced backdoor that e-mails sensitive information (hostnames, usernames, and shell history) to a fixed address.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitchx Bitchx | ||
Cypress Cypress | =1.0k |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5922 has a critical severity level due to the presence of a backdoor that compromises sensitive information.
To fix CVE-2007-5922, remove the affected Cypress 1.0k script for BitchX and use a secure version or alternative.
CVE-2007-5922 specifically affects the BitchX client and the Cypress 1.0k script.
CVE-2007-5922 compromises security by sending sensitive user information, such as hostnames and usernames, to a remote address.
Yes, CVE-2007-5922 is exploited through the backdoor introduced in the Cypress 1.0k script.