Input validation error in ZNC - CVE-2019-9917

 

Input validation error in ZNC - CVE-2019-9917

Published: April 18, 2019


Vulnerability identifier: #VU18315
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9917
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted message in incorrect encoding and cause the application to crash.


Affected software

ZNC
znc (Alpine package)
znc (Ubuntu package)
znc
Fedora
SUSE Linux
Opensuse
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2019-9917

Install updates from vendor's website.

ZNC - update to 1.7.3 rc1
znc (Alpine package) - addressed in versions 1.7.1-r1, 1.7.1-r3
znc (Ubuntu package) - update to 1.7.1-2ubuntu0.1
znc - addressed in versions 1.7.3-1.el7, 1.7.3-1.fc28, 1.7.3-1.fc29, 1.7.3-1.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins