HIGH
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request
Published Aug 4, 2009
7.5
HIGHCVSS 2.0
EPSS 2.92%
Description
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
Affected products
No data.
OR
- 0.044
- 0.045
- 0.047
- 0.052
- 0.054
- 0.056
- 0.058
- 0.060
- 0.062
- 0.064
- 0.066
- 0.068
- 0.070
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://en.znc.in/w/index.php?title=ZNC&oldid=3209#WARNING x_refsource_CONFIRM
- http://en.znc.in/wiki/ChangeLog/0.072 x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/35916 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2009/dsa-1848 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2009/07/21/5 mailing-listx_refsource_MLIST
- http://znc.svn.sourceforge.net/viewvc/znc?view=rev&sortby=rev&sortdir=down&revision=1570 x_refsource_CONFIRM
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00965.html vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| http://en.znc.in/w/index.php?title=ZNC&oldid=3209#WARNING | x_refsource_CONFIRM | |
| http://en.znc.in/wiki/ChangeLog/0.072 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://secunia.com/advisories/35916 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.debian.org/security/2009/dsa-1848 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.openwall.com/lists/oss-security/2009/07/21/5 | mailing-listx_refsource_MLIST | |
| http://znc.svn.sourceforge.net/viewvc/znc?view=rev&sortby=rev&sortdir=down&revision=1570 | x_refsource_CONFIRM | |
| https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00965.html | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 4, 2009
Updated Aug 7, 2024
Reserved Aug 4, 2009
Link CVE-2009-2658
CISA Vulnrichment
Updated n/a