* SECURITY UPDATE: The IRC Protocol component in KVIrc 3.x and 4.x before
r4693 does not properly handle \ (backslash) characters, which allows
remote authenticated users to execute arbitrary CTCP commands via vectors
involving \r and \40 sequences, a different vulnerability than CVE-2010-2451
and CVE-2010-2452.
- 33_upstream_security_#858.patch
- Patch based on upstream SVN revision 4693.
- CVE-2010-2785:
- http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2785
- LP: #612682
-- Nathan Handler <email address hidden> Sat, 12 Mar 2011 20:00:18 -0600
This bug was fixed in the package kvirc - 4:4.0.0~ svn3900+ rc2-1ubuntu0. 2
--------------- 0~svn3900+ rc2-1ubuntu0. 2) lucid-security; urgency=low
kvirc (4:4.0.
* SECURITY UPDATE: The IRC Protocol component in KVIrc 3.x and 4.x before security_ #858.patch www.cve. mitre.org/ cgi-bin/ cvename. cgi?name= 2010-2785
r4693 does not properly handle \ (backslash) characters, which allows
remote authenticated users to execute arbitrary CTCP commands via vectors
involving \r and \40 sequences, a different vulnerability than CVE-2010-2451
and CVE-2010-2452.
- 33_upstream_
- Patch based on upstream SVN revision 4693.
- CVE-2010-2785:
- http://
- LP: #612682
-- Nathan Handler <email address hidden> Sat, 12 Mar 2011 20:00:18 -0600