The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by adding a channel with the same name as an existing channel but without the leading # character, related to a use-after-delete error.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Znc | Znc | * | 1.2 (including) |
Znc | Ubuntu | lucid | * |
Znc | Ubuntu | precise | * |
Znc | Ubuntu | trusty | * |
Znc | Ubuntu | upstream | * |