Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 431
Alerts This Week
Warning Icon 1 431

Mageia: 2019-0262 Medium: ZNC Privilege Escalation and DoS Threats

mageia
Calendar Grey September 12, 2019
Scroller Mageia
The latest security patch for Mageia focuses on resolving serious flaws in ZNC, which could lead to unauthorized access and service interruptions.
Jeriko One discovered two vulnerabilities in the ZNC IRC bouncer which could result in privilege escalation or denial of service (CVE-2018-14055, CVE-2018-14056)

Summary

Jeriko One discovered two vulnerabilities in the ZNC IRC bouncer which could result in privilege escalation or denial of service (CVE-2018-14055, CVE-2018-14056).
Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917).

References

- https://bugs.mageia.org/show_bug.cgi?id=23327

- https://lists.debian.org/debian-security-announce/2018/msg00181.html

- https://lists.debian.org/debian-security-announce/2019/msg00109.html

- https://www.cve.org/CVERecord?id=CVE-2018-14055

- https://www.cve.org/CVERecord?id=CVE-2018-14056

- https://www.cve.org/CVERecord?id=CVE-2019-9917

- https://www.cve.org/CVERecord?id=CVE-2019-12816

Resolution

SRPMS

- 7/core/znc-1.7.4-1.mga7

- 6/core/znc-1.7.4-1.mga6

Severity
medium
Lowest
Low
Medium
High
Critical

Publication date: 12 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0262.html
Type: security
CVE: CVE-2018-14055, CVE-2018-14056, CVE-2019-9917, CVE-2019-12816

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.