HIGH
libsilc: multiple format string issues in handling of client entry (CVE-2009-3051) and channel name (CVE-2009-3163)
Published Sep 10, 2009
7.5
HIGHCVSS 2.0
EPSS 4.53%
Description
Multiple format string vulnerabilities in lib/silcclient/command.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client 1.1.8 and earlier, allow remote attackers to execute arbitrary code via format string specifiers in a channel name, related to (1) silc_client_command_topic, (2) silc_client_command_kick, (3) silc_client_command_leave, and (4) silc_client_command_users.
Affected products
No data.
OR
- ≤ 1.1.8
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.6
- 1.1.7
- ≤ 1.1.9
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of libsilc as shipped with Red Hat Enterprise Linux 4, or 5.
Weaknesses (1)
References (13)
- http://secunia.com/advisories/36614 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://silcnet.org/docs/changelog/SILC%20Toolkit%201.1.10 x_refsource_CONFIRM
- http://silcnet.org/general/news/news_toolkit.php x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1879 vendor-advisoryx_refsource_DEBIANVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:234 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:235 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2009/08/31/5 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/09/03/5 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/36193 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-3163 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=515648 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-3163
- https://www.cve.org/CVERecord?id=CVE-2009-3163
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 10, 2009
Updated Aug 7, 2024
Reserved Sep 10, 2009
Link CVE-2009-3163
CISA Vulnrichment
Updated n/a