CVE-2019-19010

NameCVE-2019-19010
DescriptionEval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
limnoria (PTS)stretch2017.01.10-1vulnerable
buster2019.02.23-1vulnerable
bullseye, sid2019.11.22-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
limnoriasource(unstable)2019.11.09-1

Notes

[buster] - limnoria <no-dsa> (Minor issue, can be fixed via point release)
[stretch] - limnoria <no-dsa> (Minor issue, can be fixed via point release)
https://github.com/ProgVal/Limnoria/commit/3848ae78de45b35c029cc333963d436b9d2f0a35
https://github.com/ProgVal/Limnoria/wiki/math-eval-vulnerability

Search for package or bug name: Reporting problems