VDB
CVE-2010-2785
CVE-2010-2785
PUBLISHED
CVSS 6.5 MEDIUM
The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle \ (backslash) characters, which allows remote authenticated users to execute arbitrary CTCP commands via vectors involving \r and \40 sequences, a different vulnerability than CVE-2010-2451 and CVE-2010-2452.
EPSS 7.57% · 94.2th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
7.57%
94.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| kvirc | kvirc | 3.0.0, 3.0.0, 3.0.1 |
Timeline
- Aug 2, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- FEDORA-2010-11524 vendor-advisory
- https://svn.kvirc.de/kvirc/changeset/4693 url
- https://svn.kvirc.de/kvirc/ticket/858 url
- http://bugs.gentoo.org/show_bug.cgi?id=330111 technical
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044625.html technical
- http://marc.info/?l=oss-security&m=128041011428629&w=2 patch
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html technical
- http://openwall.com/lists/oss-security/2010/07/28/1 patch
- http://www.osvdb.org/66648 technical
- https://nvd.nist.gov/vuln/detail/CVE-2010-2785 advisory
- http://secunia.com/advisories/40727 url
- http://secunia.com/advisories/40796 url