libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
References
Link | Resource |
---|---|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194 | Mailing List Patch Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438 | Issue Tracking Patch Third Party Advisory |
https://security-tracker.debian.org/tracker/CVE-2010-3438 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2019-11-12 12:15
Updated : 2019-11-14 19:21
NVD link : CVE-2010-3438
Mitre link : CVE-2010-3438
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
debian
- debian_linux
libpoe-component-irc-perl_project
- libpoe-component-irc-perl
fedoraproject
- fedora