PT-1999-1085 · Mirc · Mirc

CVE-1999-0399

·

Published

1999-01-01

·

Updated

2022-08-17

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mirc version 5.5
Description The issue concerns a problem with the DCC server command in the Mirc client, where it fails to properly filter characters from file names. This allows remote attackers to potentially place a malicious file in a different location, which could lead to the execution of commands.
Recommendations For Mirc version 5.5, consider restricting the use of the DCC server command until a proper fix is available, to minimize the risk of malicious file placement and potential command execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-0399

Affected Products

Mirc