Gentoo Logo

ZNC: Directory traversal

Content:

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 200909-17 / znc
Release Date September 13, 2009
Latest Revision September 13, 2009: 01
Impact normal
Exploitable remote
Package Vulnerable versions Unaffected versions Architecture(s)
net-irc/znc < 0.074 >= 0.074 All supported architectures

Related bugreports: #278684

Synopsis

A directory traversal was found in ZNC, allowing for overwriting of arbitrary files.

2.  Impact Information

Background

ZNC is an advanced IRC bouncer.

Description

The vendor reported a directory traversal vulnerability when processing DCC SEND requests.

Impact

A remote, authenticated user could send a specially crafted DCC SEND request to overwrite arbitrary files with the privileges of the user running ZNC, and possibly cause the execution of arbitrary code e.g. by uploading a malicious ZNC module.

3.  Resolution Information

Workaround

There is no known workaround at this time.

Resolution

All ZNC users should upgrade to the latest version:

Code Listing 3.1: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-irc/znc-0.074"

4.  References



Print

Page updated September 13, 2009

Summary: This is a Gentoo Linux Security Advisory

Security Team
Contact Address

Donate to support our development efforts.

Copyright 2001-2014 Gentoo Foundation, Inc. Questions, Comments? Contact us.