First published: Tue Nov 12 2019(Updated: )
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpoe-component-irc-perl | 6.90+dfsg-1 6.93+dfsg-1 | |
libpoe-component-irc-perl | <6.32 | |
Debian | =8.0 | |
Debian | =9.0 | |
Debian | =10.0 | |
Fedora | =12 | |
Fedora | =13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3438 has a medium severity level as it allows for arbitrary execution of IRC commands.
To fix CVE-2010-3438, upgrade libpoe-component-irc-perl to versions 6.90+dfsg-1 or 6.93+dfsg-1.
CVE-2010-3438 affects libpoe-component-irc-perl versions prior to 6.32.
Vulnerable systems include Debian and Fedora versions that have libpoe-component-irc-perl installed before version 6.32.
CVE-2010-3438 can lead to unexpected disconnections from the IRC server due to arbitrary command execution.