CVE-2009-3163

Multiple format string vulnerabilities in lib/silcclient/command.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client 1.1.8 and earlier, allow remote attackers to execute arbitrary code via format string specifiers in a channel name, related to (1) silc_client_command_topic, (2) silc_client_command_kick, (3) silc_client_command_leave, and (4) silc_client_command_users.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:silcnet:silc_toolkit:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_client:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_client:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:1.1:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_client:*:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_client:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_client:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_toolkit:1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_client:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:silcnet:silc_client:1.1.4:*:*:*:*:*:*:*

Information

Published : 2009-09-10 14:30

Updated : 2012-10-22 20:10


NVD link : CVE-2009-3163

Mitre link : CVE-2009-3163


JSON object : View

CWE
CWE-134

Use of Externally-Controlled Format String

Advertisement

dedicated server usa

Products Affected

silcnet

  • silc_toolkit
  • silc_client