Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
It was discovered that znc, an IRC proxy/bouncer, does not properly sanitize input contained in configuration change requests to the webadmin interface. This allows authenticated users to elevate their privileges and indirectly execute arbitrary commands (CVE-2009-0759). . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-1735-1
BNC contains a buffer overflow vulnerability that may lead to Denial of Service and execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: BNC: Buffer overflow vulnerability Date: November 16, 2004 Bugs: #70674 ID: 200411-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= BNC contains a buffer overflow vulnerability that may lead to Denial of Service and execution of arbitrary code. Background ========= BNC (BouNCe) is an IRC proxy server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/bnc < 2.9.1 > = 2.9.1 Description ========== Leon Juranic discovered that BNC fails to do proper bounds checking when checking server response. Impact ===== An attacker could exploit this to cause a Denial of Service and potentially execute arbitary code with the permissions of the user running BNC. Workaround ========= There is no known workaround at this time. Resolution ========= All BNC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/bnc-2.9.1" References ========= [ 1 ] BNC ChangeLog [ 2 ] LSS-2004-11-03 ;ID=LSS-2004-11-03 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200411-24 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.