Input validation error in ZNC - CVE-2019-9917
Published: April 18, 2019
Vulnerability identifier: #VU18315
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9917
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted message in incorrect encoding and cause the application to crash.
Affected software
ZNC
znc (Alpine package)
znc (Ubuntu package)
znc
Fedora
SUSE Linux
Opensuse
Dell PowerProtect Cyber Recovery
znc (Alpine package)
znc (Ubuntu package)
znc
Fedora
SUSE Linux
Opensuse
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2019-9917
Install updates from vendor's website.
ZNC - update to 1.7.3 rc1
znc (Alpine package) - addressed in versions 1.7.1-r1, 1.7.1-r3
znc (Ubuntu package) - update to 1.7.1-2ubuntu0.1
znc - addressed in versions 1.7.3-1.el7, 1.7.3-1.fc28, 1.7.3-1.fc29, 1.7.3-1.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
znc (Alpine package) - addressed in versions 1.7.1-r1, 1.7.1-r3
znc (Ubuntu package) - update to 1.7.1-2ubuntu0.1
znc - addressed in versions 1.7.3-1.el7, 1.7.3-1.fc28, 1.7.3-1.fc29, 1.7.3-1.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Denial of service in ZNC
- Ubuntu update for ZNC
- OpenSUSE Linux update for znc
- OpenSUSE Linux update for znc
- OpenSUSE Linux update for znc
- OpenSUSE Linux update for znc
- Input validation error in znc (Alpine package)
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Fedora EPEL 7 update for znc
- Fedora 30 update for znc
- Fedora 28 update for znc
- Fedora 29 update for znc