mIRC < 6.0 Long Nickname Buffer Overflow

High Nessus Network Monitor Plugin ID 1861


The remote host is running a version of mIRC that is vulnerable to a buffer overflow attack.


This issue is due to improper bounds checking of nicknames sent by the server. An excessively long nickname (200+) is capable of overwriting the stack. This issue is also exploitable via a webpage that can instruct the client to launch and to make a connection to the malicious web server. This may lead to full compromise of the host running the client software on some Windows systems.


Upgrade to version 6.0 or higher.

Plugin Details

Severity: High

ID: 1861

File Name: 1861.prm

Family: IRC Clients

Published: 2004/08/20

Modified: 2016/11/23

Dependencies: 1878

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 7.3

Temporal Score: 6.8


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Reference Information

CVE: CVE-2002-0231

BID: 4027

OSVDB: 6404