---
id: CVE-2009-20007
title: >-
  Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when
  processing specially crafted response strings sent to a connected client
summary: >-
  Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when
  processing specially crafted response strings sent to a connected client. An
  attacker can exploit this flaw by sending an overly long message that
  overflows a fi…
severity: none
cwe:
  - CWE-121
published: '2025-09-16'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T23:10:00.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2009-20007'
references:
  - url: >-
      https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/misc/talkative_response.rb
    label: disclosure@vulncheck.com
  - url: 'https://web.archive.org/web/20090116203306/http://www.talkative-irc.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/16459'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/8227'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/talkative-irc-response-buffer-overflow
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2009-4909.php'
    label: disclosure@vulncheck.com
  - url: >-
      https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/misc/talkative_response.rb
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.exploit-db.com/exploits/16459'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.exploit-db.com/exploits/8227'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2009-4909.php'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.01398
epssPercentile: 0.71441
exploits:
  metasploit:
    - exploit/windows/misc/talkative_response
  checkedAt: '2026-10-02T00:05:28.622Z'
exploitAvailable: true
ingestedAt: '2026-10-02T00:04:54.714Z'
---

## Overview

Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execution in the context of the vulnerable process. This vulnerability is exploitable remotely and does not require authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
