LWN.net Logo

znc: denial of service

Package(s):znc CVE #(s):CVE-2010-2812 CVE-2010-2934
Created:August 12, 2010 Updated:August 18, 2010
Description:

From the Red Hat bugzilla entry:

An out-of-range flaw was found in znc where if it received a "PING" from a client without an argument, std::string would throw a std::out_of_range exception which killed znc.

Some unsafe substr() calls were fixed as well. These are of lesser impact because a valid login is required in order to cause a std::out_of_range exception.

Alerts:
Fedora FEDORA-2010-12481 2010-08-11
Fedora FEDORA-2010-12468 2010-08-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds