CVE-2010-2075
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 83.5%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 83.53% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- unrealircd/unrealircd
- Source
- secalert@redhat.com
References
- http://osvdb.org/65445
- http://seclists.org/fulldisclosure/2010/Jun/277
- http://seclists.org/fulldisclosure/2010/Jun/284
- http://secunia.com/advisories/40169Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201006-21.xml
- http://www.exploit-db.com/exploits/13853
- http://www.openwall.com/lists/oss-security/2010/06/14/11
- http://www.securityfocus.com/bid/40820Exploit
- http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txtVendor Advisory
- http://www.vupen.com/english/advisories/2010/1437Vendor Advisory
- http://osvdb.org/65445
- http://seclists.org/fulldisclosure/2010/Jun/277
- http://seclists.org/fulldisclosure/2010/Jun/284
- http://secunia.com/advisories/40169Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201006-21.xml
- http://www.exploit-db.com/exploits/13853
- http://www.openwall.com/lists/oss-security/2010/06/14/11
- http://www.securityfocus.com/bid/40820Exploit
- http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txtVendor Advisory
- http://www.vupen.com/english/advisories/2010/1437Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.