CVE Vulnerabilities

CVE-2014-9403

Published: Dec 19, 2014 | Modified: Sep 29, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by adding a channel with the same name as an existing channel but without the leading # character, related to a use-after-delete error.

Affected Software

Name Vendor Start Version End Version
Znc Znc * 1.2 (including)
Znc Ubuntu lucid *
Znc Ubuntu precise *
Znc Ubuntu trusty *
Znc Ubuntu upstream *

References