PT-2009-3370 · Znc · Znc

Florian Weimer

·

Published

2009-03-03

·

Updated

2009-06-09

·

CVE-2009-0759

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZNC versions prior to 0.066
Description The issue allows remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors. This is due to multiple CRLF injection vulnerabilities in the webadmin component of ZNC.
Recommendations For versions prior to 0.066, update to version 0.066 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0759
DSA-1735-1

Affected Products

Znc