7.5
CVE-2010-2075
- EPSS 83.53%
- Veröffentlicht 15.06.2010 14:04:26
- Zuletzt bearbeitet 16.06.2026 23:19:56
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Unrealircd ≫ Unrealircd Version3.2.8.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 83.53% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://security.gentoo.org/glsa/glsa-201006-21.xml
http://osvdb.org/65445
http://seclists.org/fulldisclosure/2010/Jun/277
http://seclists.org/fulldisclosure/2010/Jun/284
http://secunia.com/advisories/40169
http://www.exploit-db.com/exploits/13853
http://www.openwall.com/lists/oss-security/2010/06/14/11
http://www.securityfocus.com/bid/40820
http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txt
http://www.vupen.com/english/advisories/2010/1437