CVE-2010-3438: Critical severity Libpoe-component-irc-perl Project Libpoe-component-irc-perl vulnerability
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3438?
CVE-2010-3438 has a medium severity level as it allows for arbitrary execution of IRC commands.
How do I fix CVE-2010-3438?
To fix CVE-2010-3438, upgrade libpoe-component-irc-perl to versions 6.90+dfsg-1 or 6.93+dfsg-1.
Which versions are affected by CVE-2010-3438?
CVE-2010-3438 affects libpoe-component-irc-perl versions prior to 6.32.
What types of systems are vulnerable to CVE-2010-3438?
Vulnerable systems include Debian and Fedora versions that have libpoe-component-irc-perl installed before version 6.32.
What impact does CVE-2010-3438 have on a system?
CVE-2010-3438 can lead to unexpected disconnections from the IRC server due to arbitrary command execution.