LWN.net Logo

znc: privilege escalation

Package(s):znc CVE #(s):CVE-2009-0759
Created:March 9, 2009 Updated:March 11, 2009
Description:

From the Gentoo advisory:

cnu discovered multiple CRLF injection vulnerabilities in ZNC's webadmin module.

A remote authenticated attacker could modify the znc.conf configuration file and gain privileges via newline characters in e.g. the QuitMessage field, and possibly execute arbitrary code.

Alerts:
Debian DSA-1735-1 2009-03-10
Gentoo 200903-02 2009-03-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds