|
|
| |
|
| |
znc: privilege escalation
| Package(s): | znc |
CVE #(s): | CVE-2009-0759
|
| Created: | March 9, 2009 |
Updated: | March 11, 2009 |
| Description: |
From the Gentoo advisory:
cnu discovered multiple CRLF injection vulnerabilities in ZNC's
webadmin module.
A remote authenticated attacker could modify the znc.conf configuration
file and gain privileges via newline characters in e.g. the QuitMessage
field, and possibly execute arbitrary code.
|
| Alerts: |
|
( Log in to post comments)
|
|
|