Описание
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| znc | fixed | 1.7.2-2 | package | |
| znc | ignored | jessie | package |
Примечания
https://github.com/znc/znc/commit/64613bc8b6b4adf1e32231f9844d99cd512b8973
Every version between 0.096 and 1.7.2 (incl) is vulnerable to the issue,
but earlier versions could not be fixed without a major rewrite. A workaround
though is to disable modpython.
EPSS
Связанные уязвимости
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
Уязвимость модулей src/User.cpp, src/znc.cpp, src/IRCNetwork.cpp механизма отключения клиентов от IRC-сервера или выбранного канала ZNC, позволяющая нарушителю вызвать отказ в обслуживании
EPSS