peter bassill · operator
$ cve CVE-2003-0478 JSON

CVE-2003-0478 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 12.3% (pctl 96)

Patch early

A public exploit exists.

Description

Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS12.28% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2003-08-07
Last modified2026-06-16

Affected (5)

VendorProduct
andromedeadromedeircd
bahamutircd
daniel mossmethane
hans westerhofdigatech
wenetircd-ru

Public exploits

SourceTitleDate
exploit-dbmethane IRCd 0.1.1 - Remote Format String2003-06-27

References

→ the Explorer  ·  watch your stack  ·  NVD