PT-2019-2934 · Znc+2 · Znc+2
Darthgandalf
·
Published
2019-03-27
·
Updated
2024-06-15
·
CVE-2019-9917
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ZNC versions prior to 1.7.3-rc1
Description
The issue allows an existing remote user to cause a Denial of Service (crash) via invalid encoding. It is due to insufficient input validation in the mechanism for disconnecting clients from the IRC server or a selected channel. This can be exploited by a remote attacker to cause a denial of service.
Recommendations
For versions prior to 1.7.3-rc1, update to version 1.7.3-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ZNC service to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Ubuntu
Znc