libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
References
Link | Resource |
---|---|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194 | Mailing List Patch Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438 | Issue Tracking Patch Third Party Advisory |
https://security-tracker.debian.org/tracker/CVE-2010-3438 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2019-11-12T19:43:05
Updated: 2019-11-12T19:43:05
Reserved: 2010-09-17T00:00:00
Link: CVE-2010-3438
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-11-12T20:15:09.730
Modified: 2019-11-15T03:21:58.293
Link: CVE-2010-3438
JSON object: View
Redhat Information
No data.
CWE