Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Mageia 9: 2024-0257 Critical: ZNC Remote Code Execution in ModTCL

mageia
Calendar Grey July 5, 2024
Scroller Mageia
XYZ toolkit patches mitigate vulnerabilities linked to unauthorized access in Fedora. Urgent notice and fixes released starting August 10, 2024.
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK

Summary

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK. (CVE-2024-39844)

References

- https://bugs.mageia.org/show_bug.cgi?id=33364

- https://www.openwall.com/lists/oss-security/2024/07/03/9

- https://www.cve.org/CVERecord?id=CVE-2024-39844

Resolution

SRPMS

- 9/core/znc-1.8.2-21.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Jul 2024
URL: https://advisories.mageia.org/MGASA-2024-0257.html
Type: security
CVE: CVE-2024-39844

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.