Vulnerability Name: | CVE-2010-3438 (CCN-174855) | ||||||||||||
Assigned: | 2010-05-11 | ||||||||||||
Published: | 2010-05-11 | ||||||||||||
Updated: | 2019-11-15 | ||||||||||||
Summary: | libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-134 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-3438 Source: MISC Type: Mailing List, Patch, Third Party Advisory https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194 Source: CCN Type: Red Hat Bugzilla Bug 591215 (CVE-2010-3438) - CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438 Source: XF Type: UNKNOWN libpoe-cve20103438-cmd-exec(174855) Source: CCN Type: libpoe-component-irc-perl Web site libpoe-component-irc-perl Source: MISC Type: Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2010-3438 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |