CVE-2007-4396
Publication date 18 August 2007
Last updated 24 July 2024
Ubuntu priority
Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
Status
Package | Ubuntu Release | Status |
---|---|---|
irssi-scripts | 9.10 karmic |
Fixed 20070925
|
9.04 jaunty |
Fixed 20070925
|
|
8.10 intrepid |
Fixed 20070925
|
|
8.04 LTS hardy |
Fixed 20070925
|
|
7.10 gutsy |
Fixed 20070925
|
|
7.04 feisty | Ignored end of life, was needed | |
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |