Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 31: FEDORA-2019-233d9b9a5e critical: znc Remote Code Execution

fedora
Calendar Grey October 6, 2019
Dist Fedora Esm H88
The recent znc 1.7.5 update on Fedora 31 resolves a critical remote code execution vulnerability; refer to the advisory for complete information.
Update to 1.7.5 ---- Fixes CVE-2019-12816

Summary

ZNC is an IRC bouncer with many advanced features like detaching,

multiple users, per channel playback buffer, SSL, IPv6, transparent

DCC bouncing, Perl and C++ module support to name a few.

Update to 1.7.5 ---- Fixes CVE-2019-12816

[ 1 ] Bug #1718369 - znc fails to build with Python 3.8

https://bugzilla.redhat.com/show_bug.cgi?id=1718369

[ 2 ] Bug #1720886 - znc-1.7.5-rc1 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1720886

[ 3 ] Bug #1726159 - CVE-2019-12816 znc: invalid encoding leading to remote code execution [epel-7]

https://bugzilla.redhat.com/show_bug.cgi?id=1726159

[ 4 ] Bug #1726160 - CVE-2019-12816 znc: invalid encoding leading to remote code execution [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1726160

su -c 'dnf upgrade --advisory FEDORA-2019-233d9b9a5e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 1.7.5
Release: 1.fc31
Summary: An advanced IRC bouncer

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here