CVE-2008-7070

NameCVE-2008-7070
DescriptionArgument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followed by command line switches in a (1) irc:///, (2) irc6:///, (3) ircs:///, or (4) and ircs6:/// URI. NOTE: this might be due to an incomplete fix for CVE-2007-2951.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kvirc (PTS)buster4:5.0.0+dfsg-1fixed
bullseye4:5.0.0+dfsg-5fixed
trixie, bookworm4:5.0.0+dfsg-6fixed
sid4:5.2.2+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kvircsource(unstable)(not affected)

Notes

- kvirc <not-affected> (Only affects Windows builds)
https://svn.kvirc.de/kvirc/ticket/274#comment:8

Search for package or bug name: Reporting problems