Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Talkative IRC Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Talkative IRC version 0.4.4.16. This issue arises when the application processes specially crafted response strings sent to a connected client. An attacker can exploit this vulnerability by sending an excessively long message that overflows a fixed-length buffer, potentially leading to arbitrary code execution within the context of the vulnerable process. The vulnerability can be exploited remotely and does not require authentication.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Reproduction

The vulnerability can be reproduced by sending a crafted response string that exceeds the buffer limit to a client connected to a malicious IRC server. This can be done using the Metasploit Framework, which includes an exploit module for this vulnerability.

Added: Sep 16, 2025, 3:46 PM
Updated: Sep 16, 2025, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
9.1
remediation
0.0
relevance
0.5
threat
9.3
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.