CVE-2007-4399: CRLF Injection
CRLF injection vulnerability in the xmms.bx 1.0 script for BitchX allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4399?
CVE-2007-4399 is classified as a medium severity vulnerability due to the potential for user-assisted remote command execution.
How do I fix CVE-2007-4399?
To fix CVE-2007-4399, ensure that you update to a patched version of the xmms.bx script and avoid processing untrusted .mp3 files.
Which versions are affected by CVE-2007-4399?
CVE-2007-4399 affects the xmms.bx script in BitchX versions prior to the patch release.
What type of attack does CVE-2007-4399 enable?
CVE-2007-4399 enables user-assisted remote attackers to execute arbitrary IRC commands through CRLF injection.
Who is affected by CVE-2007-4399?
Users of BitchX using the vulnerable xmms.bx script and those who play untrusted .mp3 files may be affected by CVE-2007-4399.