← Back

CVE-2007-3246

nvd nist
Published: Jun 15, 2007Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The do_set_password function in modules/chanserv/set.c in IRC Services before 5.0.60 preserves channel founder privileges across a channel password change (ChanServ SET PASSWORD), which allows remote authenticated users to obtain the new password through automated e-mail, or perform privileged actions without knowing the new password.

Affected (1)

1 product
Irc Services
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.0.60

References (10)

Timeline

No history available yet.