SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-4127

Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a)…

MEDIUM 4.6EPSS 2.24%

Does this matter?

Lower severity and a low EPSS score (2.24%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a) cmd.user.c, (b) penalties.c, or (c) cmd.dc.c.

CVSS 2.0
4.6 MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
EPSS
2.24% probability · 82th percentile
CISA KEV
Not listed
Affected
dconnect/dconnect daemon
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.