Package "znc-tcl"
| Name: |
znc-tcl
|
Description: |
advanced modular IRC bouncer (Tcl extension)
|
| Latest version: |
1.6.6-1ubuntu0.2 |
| Release: |
bionic (18.04) |
| Level: |
security |
| Repository: |
universe |
| Head package: |
znc |
| Homepage: |
https://www.znc.in/ |
Links
Download "znc-tcl"
Other versions of "znc-tcl" in Bionic
Changelog
|
znc (1.6.6-1ubuntu0.2) bionic-security; urgency=medium
* SECURITY UPDATE: Fix vulnerability that allows remote authenticated
non-admin users to escalate privileges and execute arbitrary code by
loading a module with a crafted name.
- debian/patches/CVE-2019-12816.patch: Fix remote code execution and
privilege escalation.
- CVE-2019-12816
-- Paulo Flabiano Smorigo <email address hidden> Tue, 25 Jun 2019 15:52:19 -0300
|
| Source diff to previous version |
| CVE-2019-12816 |
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module |
|
|
znc (1.6.6-1ubuntu0.1) bionic-security; urgency=medium
* SECURITY UPDATE: Privilege escalation for non-admin users (LP: #1781925)
- debian/patches/CVE-2018-14055-1.patch: Remove newlines from incoming
network configuration change directives. Based on upstream patch.
- debian/patches/CVE-2018-14055-2.patch: Remove extra newlines when
writing out configuration file. Based on upstream patch.
- CVE-2018-14055
* SECURITY UPDATE: Path traversal flaw allows access to files outside of
skins (LP: #1781925)
- debian/patches/CVE-2018-14056.patch: Replace path traversal components
in skin names to ensure path traversal is not possible. Based on
upstream patch.
- CVE-2018-14056
-- Alex Murray <email address hidden> Thu, 26 Jul 2018 15:28:39 +0930
|
| 1781925 |
Vulnerabilities in znc package CVE-2018-14055 CVE-2018-14056 |
| CVE-2018-14055 |
ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inje |
| CVE-2018-14056 |
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories. |
|
About
-
Send Feedback to @ubuntu_updates