|
|
| |
|
| |
znc: denial of service
| Package(s): | znc |
CVE #(s): | CVE-2010-2812
CVE-2010-2934
|
| Created: | August 12, 2010 |
Updated: | August 18, 2010 |
| Description: |
From the Red Hat bugzilla entry:
An out-of-range flaw was found in znc where if it received a "PING" from a
client without an argument, std::string would throw a std::out_of_range
exception which killed znc.
Some unsafe substr() calls were fixed as well. These are of lesser impact
because a valid login is required in order to cause a std::out_of_range
exception. |
| Alerts: |
|
( Log in to post comments)
|
|
|