CVE-2010-3438
published 2019-11-12CVE-2010-3438: libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.65%
73.9th percentile
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libpoe-component-irc-perl | < libpoe-component-irc-perl 6.32+dfsg-1 (bookworm) | libpoe-component-irc-perl 6.32+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libpoe-component-irc-perl | libpoe-component-irc-perl | — | — |
| libpoe-component-irc-perl | libpoe-component-irc-perl | >= 0 < 6.32+dfsg-1 | 6.32+dfsg-1 |
| libpoe-component-irc-perl | libpoe-component-irc-perl | >= 0 < 6.32+dfsg-1 | 6.32+dfsg-1 |
| libpoe-component-irc-perl | libpoe-component-irc-perl | >= 0 < 6.32+dfsg-1 | 6.32+dfsg-1 |
| libpoe-component-irc-perl | libpoe-component-irc-perl | >= 0 < 6.32+dfsg-1 | 6.32+dfsg-1 |
| libpoe-component-irc-perl_project | libpoe-component-irc-perl | < 6.32 | 6.32 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vqr8-85pj-78rw: libpoe-component-irc-perl before v6
ghsa_unreviewed·2022-04-21
CVE-2010-3438 [HIGH] GHSA-vqr8-85pj-78rw: libpoe-component-irc-perl before v6
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
OSV
CVE-2010-3438: libpoe-component-irc-perl before v6
osv·2019-11-12·CVSS 9.8
CVE-2010-3438 [CRITICAL] CVE-2010-3438: libpoe-component-irc-perl before v6
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Debian
CVE-2010-3438: libpoe-component-irc-perl - libpoe-component-irc-perl before v6.32 does not remove carriage returns and line...
vendor_debian·2010·CVSS 9.8
CVE-2010-3438 [CRITICAL] CVE-2010-3438: libpoe-component-irc-perl - libpoe-component-irc-perl before v6.32 does not remove carriage returns and line...
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Scope: local
bookworm: resolved (fixed in 6.32+dfsg-1)
bullseye: resolved (fixed in 6.32+dfsg-1)
forky: resolved (fixed in 6.32+dfsg-1)
sid: resolved (fixed in 6.32+dfsg-1)
trixie: resolved (fixed in 6.32+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF [fedora-all]
bugzilla·2010-12-16·CVSS 9.8
CVE-2010-3438 [CRITICAL] CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF [fedora-all]
CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=6
Bugzilla
CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF
bugzilla·2010-05-11·CVSS 9.8
CVE-2010-3438 [CRITICAL] CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF
CVE-2010-3438 perl-POE-Component-IRC: arbitrary IRC command execution due to insufficient stripping of CR/LF
A vulnerability was reported [1] to Debian for POE::Component::IRC, where it did not remove carriage returns and line feeds. This affects tools or IRC bots using the perl module, and can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Upstream has fixed [2],[3],[4] the issue and it is included in the current 6.32 release.
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194
[2] http://github.com/bingos/poe-component-irc/commit/4f46c29376359b3d7c5b5cd400115103fdef9ca8
[3] http://github.com/bingos/poe-component-irc/commit/675f55cd40ceebbc1bd2f30931
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438https://security-tracker.debian.org/tracker/CVE-2010-3438https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438https://security-tracker.debian.org/tracker/CVE-2010-3438
2019-11-12
Published