#VU29532 NULL pointer dereference in ZNC - CVE-2020-13775
Published: July 6, 2020
ZNC
ZNC
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote authenticated user can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that the echo-message is not enabled and there is no network.
Remediation
External links
- https://github.com/znc/znc/commit/2390ad111bde16a78c98ac44572090b33c3bd2d8
- https://github.com/znc/znc/commit/d229761821da38d984a9e4098ad96842490dc001
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNVBE4T2DRJRQHFRMHYBTN4OSOL6DBHR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HS3DWGXLVRROQQA57UIPMDM6XMVEMBRA/