PT-2019-2933 · Znc+2 · Znc+2

Jeriko One

·

Published

2019-06-12

·

Updated

2024-06-15

·

CVE-2019-12816

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZNC versions prior to 1.7.4-rc1
Description The issue is related to insufficient privilege control in the LoadModule, GetModInfo, and GetModPathInfo functions from src/Modules.cpp, which are part of the mechanism for disconnecting clients from an IRC server or a selected ZNC channel. This can be exploited by a remote attacker to elevate privileges and execute arbitrary code by loading a module with a specially crafted user name.
Recommendations For versions prior to 1.7.4-rc1, update to version 1.7.4-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to the LoadModule function to prevent non-admin users from loading modules until a patch is applied.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02908
CVE-2019-12816
DLA-1830-1
DSA-4463-1
MGASA-2019-0262
OPENSUSE-SU-2019:1775-1
OPENSUSE-SU-2019:1859-1
OPENSUSE-SU-2019_1775-1
OPENSUSE-SU-2024:11542-1
USN-4044-1

Affected Products

Suse
Ubuntu
Znc