Description
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
References (4)
Core 4
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/znc/znc/commit/2390ad111bde16a78c98ac44572090b33c3bd2d8
Patch, Third Party Advisory x_refsource_confirm
https://github.com/znc/znc/commit/d229761821da38d984a9e4098ad96842490dc001
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HS3DWGXLVRROQQA57UIPMDM6XMVEMBRA/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DNVBE4T2DRJRQHFRMHYBTN4OSOL6DBHR/
Scores
CVSS v3
6.5
EPSS
0.0097
EPSS Percentile
76.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (3)
fedoraproject/fedora
31
fedoraproject/fedora
32
znc/znc
1.8.0
Published
Jun 02, 2020
Tracked Since
Feb 18, 2026