CVE-2023-50784

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
16/12/2023
Last modified:
26/12/2023

Description

A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker to crash the server by sending an oversized packet (if a websocket port is open). Remote code execution might be possible on some uncommon, older platforms.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unrealircd:unrealircd:*:*:*:*:*:*:*:* 6.1.0 (including) 6.1.4 (excluding)