Back to search
CVE-2010-2448
Published: Jul 12, 2010
Modified: Sep 16, 2024
PUBLISHED
Description
znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2010-1775
vdb-entry
x_refsource_VUPEN
FEDORA-2010-10078
vendor-advisory
x_refsource_FEDORA
40523
third-party-advisory
x_refsource_SECUNIA
40982
vdb-entry
x_refsource_BID
http://znc.svn.sourceforge.net/viewvc/znc?revision=2026&view=revision
x_refsource_CONFIRM
FEDORA-2010-10042
vendor-advisory
x_refsource_FEDORA
FEDORA-2010-10082
vendor-advisory
x_refsource_FEDORA
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584929
x_refsource_CONFIRM
DSA-2069
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now