Package: konversation
Version: 1.0.1-1
Severity: minor
Tags: security

A vulnerability has been found in conversation. From CVE-2007-4400:

"CRLF injection vulnerability in the included media script in
Konversation allows user-assisted remote attackers to execute
arbitrary IRC commands via CRLF sequences in the name of the song in a
.mp3 file."

Severity minor since the attack vector is rather obscure.

Please mention the CVE id in the changelog.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to