CVE-2010-3438
Summary
| CVE | CVE-2010-3438 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-12 20:15:00 UTC |
| Updated | 2019-11-15 03:21:00 UTC |
| Description | libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server. |
Risk And Classification
Problem Types: CWE-134
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 12 | All | All | All |
| Operating System | Fedoraproject | Fedora | 13 | All | All | All |
| Operating System | Fedoraproject | Fedora | 12 | All | All | All |
| Operating System | Fedoraproject | Fedora | 13 | All | All | All |
| Application | Libpoe-component-irc-perl Project | Libpoe-component-irc-perl | All | All | All | All |
| Application | Libpoe-component-irc-perl Project | Libpoe-component-irc-perl | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 591215 – (CVE-2010-3438) CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF | MISC | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| #581194 - libpoe-component-irc-perl: Insufficient stripping of CR/LF allows arbitrary IRC command execution - Debian Bug report logs | MISC | bugs.debian.org | Mailing List, Patch, Third Party Advisory |
| CVE-2010-3438 | MISC | security-tracker.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.