J-Security Center

Title: WircSrv MOTD Read Vulnerability

Severity: MODERATE

Description:

Certain versions of WircSrv, a personal IRC server for Windows NT or Windows, have a vulnerability which allows certain users to read files to which they possibly should not have access to. This vulnerability is via a command within the server which is accessible only to pre-authorized IRCop's (moderators for the IRC server). This command is supposed to allow the user to access an MOTD (Message Of The Day) for display inside of the IRC session (displayed to users upon login). However, instead of simply allowing access to a prearranged file it allows access to any file within the permission range of the user running the server.

Affected Products:

  • WircSrv IRC Server 5.0.7s

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.