CVE-2007-4398: CRLF Injection
Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4398?
CVE-2007-4398 is considered to have a moderate severity due to its potential for user-assisted exploitation.
How do I fix CVE-2007-4398?
To fix CVE-2007-4398, ensure you are using a version of the affected scripts that is not vulnerable, such as upgrading to the latest version of WeeChat's now-playing.rb and xmms.pl.
What systems are affected by CVE-2007-4398?
CVE-2007-4398 affects the now-playing.rb and xmms.pl scripts specifically in versions of WeeChat and related software.
What types of attacks can exploit CVE-2007-4398?
CVE-2007-4398 can be exploited for arbitrary IRC command execution through CRLF injection in song names.
Who is at risk from CVE-2007-4398?
Users of affected versions of WeeChat who interact with maliciously crafted .mp3 files are at risk from CVE-2007-4398.