Vulnerabilities > CVE-2007-4398 - Unspecified vulnerability in Irssi
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
Vulnerable Configurations
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065227.html
- http://wouter.coekaerts.be/site/security/nowplaying
- http://www.securityfocus.com/bid/25281
- http://secunia.com/advisories/26457
- http://secunia.com/advisories/26490
- http://securityreason.com/securityalert/3036
- http://osvdb.org/39565
- http://osvdb.org/39564
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35985
- http://www.securityfocus.com/archive/1/476283/100/0/threaded
- http://git.sv.gnu.org/gitweb/?p=weechat/scripts.git%3Ba=commit%3Bh=7429c29a2fab6d7493c0188b5f631a7c2ae1533d
- http://git.sv.gnu.org/gitweb/?p=weechat/scripts.git%3Ba=commit%3Bh=76f7f7b502352ba2b823e3388a2ca88840fd1945