CVE-2010-3438
Last modified
CVE-2010-3438 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.. EPSS estimates a 1.65% chance of exploitation in the next 30 days.
Description
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libpoe-Component-Irc-Perl Project | Libpoe-Component-Irc-Perl | < 6.32 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Fedoraproject | Fedora | 12 |
| Fedoraproject | Fedora | 13 |
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438Issue Tracking, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2010-3438Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581194Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3438Issue Tracking, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2010-3438Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3438?
How severe is CVE-2010-3438?
How do I fix CVE-2010-3438?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3432The sctp_packet_config function in net/sctp/output.c in the …
- CVE-2010-3433The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 bef…
- CVE-2010-3434Buffer overflow in the find_stream_bounds function in pdf.c …
- CVE-2010-3435The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka p…
- CVE-2010-3436fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remo…
- CVE-2010-3437Integer signedness error in the pkt_find_dev_from_minor func…
- CVE-2010-3439It is possible to cause a DoS condition by causing the serve…6.5
- CVE-2010-3440babiloo 2.0.9 before 2.0.11 creates temporary files with pre…5.5
- CVE-2010-3441Multiple buffer overflows in abcm2ps before 5.9.12 might all…
- CVE-2010-3442Multiple integer overflows in the snd_ctl_new function in so…
- CVE-2010-3443ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7…
- CVE-2010-3444Buffer overflow in the log2vis_utf8 function in pyfribidi.c …
Are you affected by CVE-2010-3438?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
