GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Mar 06, 2009 11:26 pm Post subject: [ GLSA 200903-02 ] ZNC: Privilege escalation |
|
|
Gentoo Linux Security Advisory
Title: ZNC: Privilege escalation (GLSA 200903-02)
Severity: high
Exploitable: remote
Date: March 06, 2009
Bug(s): #260148
ID: 200903-02
Synopsis
A vulnerability in ZNC allows for privilege escalation.
Background
ZNC is an advanced IRC bouncer.
Affected Packages
Package: net-irc/znc
Vulnerable: < 0.066
Unaffected: >= 0.066
Architectures: All supported architectures
Description
cnu discovered multiple CRLF injection vulnerabilities in ZNC's webadmin module.
Impact
A remote authenticated attacker could modify the znc.conf configuration file and gain privileges via newline characters in e.g. the QuitMessage field, and possibly execute arbitrary code.
Workaround
There is no known workaround at this time.
Resolution
All ZNC users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-irc/znc-0.066" |
References
CVE-2009-0759 |
|