6.8
CVSSv2

CVE-2007-4398

Published: 18/08/2007 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote malicious users to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.

Vulnerable Product Search on Vulmon Subscribe to Product

irssi irssi

Vendor Advisories

Debian Bug report logs - #439840 CVE-2007-4398, CVE-2007-4396: Multiple CRLF injection vulnerabilities Package: irssi-scripts; Maintainer for irssi-scripts is Daniel Echeverry <epsilon@debianorg>; Source for irssi-scripts is src:irssi-scripts (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: M ...
Debian Bug report logs - #439839 CVE-2007-4398: Multiple CRLF injection vulnerabilities Package: weechat-scripts; Maintainer for weechat-scripts is Emmanuel Bouthenot <kolter@debianorg>; Source for weechat-scripts is src:weechat-scripts (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 27 ...