libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
References
Link | Resource |
---|---|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194 | Mailing List Patch Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438 | Issue Tracking Patch Third Party Advisory |
https://security-tracker.debian.org/tracker/CVE-2010-3438 | Third Party Advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194 | Mailing List Patch Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438 | Issue Tracking Patch Third Party Advisory |
https://security-tracker.debian.org/tracker/CVE-2010-3438 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 01:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194 - Mailing List, Patch, Third Party Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://security-tracker.debian.org/tracker/CVE-2010-3438 - Third Party Advisory |
Information
Published : 2019-11-12 20:15
Updated : 2024-11-21 01:18
NVD link : CVE-2010-3438
Mitre link : CVE-2010-3438
CVE.ORG link : CVE-2010-3438
JSON object : View
Products Affected
debian
- debian_linux
libpoe-component-irc-perl_project
- libpoe-component-irc-perl
fedoraproject
- fedora
CWE
CWE-134
Use of Externally-Controlled Format String