CVE-2019-19010: Code Injection
Published Nov 16, 2019
·Updated
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
Affected Software
5 affected componentsFixes available
pip/limnoria<2019.11.09
2019.11.09
Limnoria Project Limnoria<2019.11.09
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Remediation
Event History
Nov 16, 2019
CVE Published
via MITRE·12:52 AM
Data Sourced
via MITRE·12:52 AM
Description
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 20, 2019
Advisory Published
01:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2019-19010?
CVE-2019-19010 is categorized as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2019-19010?
To fix CVE-2019-19010, upgrade Limnoria to version 2019.11.09 or later.
3
What software is affected by CVE-2019-19010?
CVE-2019-19010 affects Limnoria prior to version 2019.11.09 and Supybot through 2018-05-09.
4
Is there a risk of data breach with CVE-2019-19010?
Yes, CVE-2019-19010 allows remote unprivileged attackers to potentially disclose sensitive information.
5
What commands are involved in CVE-2019-19010?
The vulnerable commands in CVE-2019-19010 are the calc and icalc IRC commands.