CVE Vulnerabilities

CVE-2014-9403

Published: Dec 19, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by adding a channel with the same name as an existing channel but without the leading # character, related to a use-after-delete error.

Affected Software

NameVendorStart VersionEnd Version
ZncZnc*1.2 (including)
ZncUbuntuesm-infra-legacy/trusty*
ZncUbuntulucid*
ZncUbuntuprecise*
ZncUbuntutrusty*
ZncUbuntutrusty/esm*
ZncUbuntuupstream*

References