ZNC 'CWebAdminMod::ChanPage()' Function Denial of Service Vulnerability
BID:66926
Info
ZNC 'CWebAdminMod::ChanPage()' Function Denial of Service Vulnerability
| Bugtraq ID: | 66926 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-9403 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2014 12:00AM |
| Updated: | Apr 13 2015 09:41PM |
| Credit: | Russell Bradford |
| Vulnerable: |
ZNC ZNC 1.2 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 |
| Not Vulnerable: | |
Discussion
ZNC 'CWebAdminMod::ChanPage()' Function Denial of Service Vulnerability
ZNC is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to crash the application, denying service to legitimate users.
ZNC 1.2 is vulnerable; other versions may also be affected.
ZNC is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to crash the application, denying service to legitimate users.
ZNC 1.2 is vulnerable; other versions may also be affected.
Solution / Fix
ZNC 'CWebAdminMod::ChanPage()' Function Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva znc-1.0-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva znc-devel-1.0-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
ZNC 'CWebAdminMod::ChanPage()' Function Denial of Service Vulnerability
References:
References:
- Crash while adding channels to the web admin (Russell Bradford)
- webadmin/add channel: Correctly handle channel names (ZNC)
- ZNC Home Page (ZNC)