CVE-2007-4396

NameCVE-2007-4396
DescriptionMultiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs439840

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
irssi-scripts (PTS)bullseye20201016fixed
bookworm20220704fixed
sid, trixie20231031fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
irssi-scriptssource(unstable)20070925low439840

Notes

[etch] - irssi-scripts <no-dsa> (minor issue)
[sarge] - irssi-scripts <no-dsa> (minor issue)
weechat-scripts does not include the mentioned scripts

Search for package or bug name: Reporting problems