libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2019-11-12T19:43:05

Updated: 2024-08-07T03:11:44.290Z

Reserved: 2010-09-17T00:00:00

Link: CVE-2010-3438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-11-12T20:15:09.730

Modified: 2019-11-15T03:21:58.293

Link: CVE-2010-3438

cve-icon Redhat

No data.