libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2019-11-12T19:43:05

Updated: 2024-08-07T03:11:44.290Z

Reserved: 2010-09-17T00:00:00

Link: CVE-2010-3438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-12T20:15:09.730

Modified: 2024-11-21T01:18:44.453

Link: CVE-2010-3438

cve-icon Redhat

No data.