CVE-2019-19010
published 2019-11-16CVE-2019-19010: Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.33%
81.8th percentile
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | limnoria | < limnoria 2019.11.09-1 (bookworm) | limnoria 2019.11.09-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| limnoria_project | limnoria | < 2019.11.09 | 2019.11.09 |
| limnoria_project | limnoria | >= 0 < 2019.11.09-1 | 2019.11.09-1 |
| limnoria_project | limnoria | >= 0 < 2019.11.09-1 | 2019.11.09-1 |
| limnoria_project | limnoria | >= 0 < 2019.11.09-1 | 2019.11.09-1 |
| limnoria_project | limnoria | >= 0 < 2019.11.09-1 | 2019.11.09-1 |
| limnoria_project | limnoria | >= 0 < 2019.11.09 | 2019.11.09 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-19010: limnoria - Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (t...
vendor_debian·2019·CVSS 9.8
CVE-2019-19010 [CRITICAL] CVE-2019-19010: limnoria - Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (t...
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
Scope: local
bookworm: resolved (fixed in 2019.11.09-1)
bullseye: resolved (fixed in 2019.11.09-1)
forky: resolved (fixed in 2019.11.09-1)
sid: resolved (fixed in 2019.11.09-1)
trixie: resolved (fixed in 2019.11.09-1)
OSV
Eval injection in Supybot/Limnoria
osv·2019-11-20
CVE-2019-19010 [CRITICAL] Eval injection in Supybot/Limnoria
Eval injection in Supybot/Limnoria
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
GHSA
Eval injection in Supybot/Limnoria
ghsa·2019-11-20
CVE-2019-19010 [CRITICAL] CWE-94 Eval injection in Supybot/Limnoria
Eval injection in Supybot/Limnoria
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
OSV
CVE-2019-19010: Eval injection in the Math plugin of Limnoria (before 2019
osv·2019-11-16·CVSS 9.8
CVE-2019-19010 [CRITICAL] CVE-2019-19010: Eval injection in the Math plugin of Limnoria (before 2019
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19010 supybot: limnoria: information disclosure via calc and icalc IRC command [epel-6]
bugzilla·2020-04-02·CVSS 9.8
CVE-2019-19010 [CRITICAL] CVE-2019-19010 supybot: limnoria: information disclosure via calc and icalc IRC command [epel-6]
CVE-2019-19010 supybot: limnoria: information disclosure via calc and icalc IRC command [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templa
Bugzilla
CVE-2019-19010 limnoria: information disclosure via calc and icalc IRC command
bugzilla·2020-04-02·CVSS 9.8
CVE-2019-19010 [CRITICAL] CVE-2019-19010 limnoria: information disclosure via calc and icalc IRC command
CVE-2019-19010 limnoria: information disclosure via calc and icalc IRC command
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
Reference:
https://github.com/ProgVal/Limnoria/commit/3848ae78de45b35c029cc333963d436b9d2f0a35
https://github.com/ProgVal/Limnoria/wiki/math-eval-vulnerability
https://lists.fedoraproject.org/archives/list/[email protected]/message/54CQM2TEXRADLE77VOMCPHL5PBHR3ZWJ/
https://lists.fedoraproject.org/archives/list/[email protected]/message/5P2AGND54UIJV3WHOYO2YINIXSDGAAPO/
https://lists.fedoraproject.org/archives/list/package-announce
Bugzilla
CVE-2019-19010 supybot: limnoria: information disclosure via calc and icalc IRC command [fedora-30]
bugzilla·2020-04-02·CVSS 9.8
CVE-2019-19010 [CRITICAL] CVE-2019-19010 supybot: limnoria: information disclosure via calc and icalc IRC command [fedora-30]
CVE-2019-19010 supybot: limnoria: information disclosure via calc and icalc IRC command [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following
https://github.com/ProgVal/Limnoria/commit/3848ae78de45b35c029cc333963d436b9d2f0a35https://github.com/ProgVal/Limnoria/wiki/math-eval-vulnerabilityhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/54CQM2TEXRADLE77VOMCPHL5PBHR3ZWJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P2AGND54UIJV3WHOYO2YINIXSDGAAPO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DRNOUHFEN75QAIKT4Y3HDN3TT5LSIWN2/https://github.com/ProgVal/Limnoria/commit/3848ae78de45b35c029cc333963d436b9d2f0a35https://github.com/ProgVal/Limnoria/wiki/math-eval-vulnerabilityhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/54CQM2TEXRADLE77VOMCPHL5PBHR3ZWJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P2AGND54UIJV3WHOYO2YINIXSDGAAPO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DRNOUHFEN75QAIKT4Y3HDN3TT5LSIWN2/
2019-11-16
Published