CVE-2019-19010

NameCVE-2019-19010
DescriptionEval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
limnoria (PTS)buster2019.02.23-1+deb10u1fixed
bullseye2021.06.15-1fixed
bookworm2023.1.28-1fixed
sid, trixie2023.11.18-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
limnoriasourcestretch2017.01.10-1+deb9u1
limnoriasourcebuster2019.02.23-1+deb10u1
limnoriasource(unstable)2019.11.09-1

Notes

https://github.com/ProgVal/Limnoria/commit/3848ae78de45b35c029cc333963d436b9d2f0a35
https://github.com/ProgVal/Limnoria/wiki/math-eval-vulnerability

Search for package or bug name: Reporting problems