|
Message-ID: <5a4f0d9d-7bbf-489d-bac2-ed5789105882@linuxlounge.net> Date: Wed, 3 Jul 2024 18:18:36 +0200 From: Martin Weinelt <martin@...uxlounge.net> To: oss-security@...ts.openwall.com Subject: CVE-2024-39844: ZNC modtcl RCE Hi, ZNC before 1.9.1 has a remote code execution vulnerability in its modtcl module, that can for example be triggered through a prepared kick message https://wiki.znc.in/ChangeLog/1.9.1 Alternatively the following patch needs to be applied to mitigate this vulnerability: https://github.com/znc/znc/commit/8cbf8d628174ddf23da680f3f117dc54da0eb06e The vulnerability was discovered and reported by Johannes Kuhn (DasBrain). The patch was created by glguy. --- Martin
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.