A vulnerability has been found in ZNC which could result in remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202409-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ZNC: Remote Code Execution Date: September 24, 2024 Bugs: #935422 ID: 202409-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in ZNC which could result in remote code execution. Background ========== ZNC is an advanced IRC bouncer. Affected packages ================= Package Vulnerable Unaffected ----------- ------------ ------------ net-irc/znc < 1.9.1 > = 1.9.1 Description =========== ZNC's modtcl could allow for remote code execution via a KICK. Impact ====== A vulnerable ZNC with the modtcl module loaded could be exploited for remote code execution. Workaround ========== Unload the mod_tcl module. Resolution ========== All ZNC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/znc-1.9.1" References ========== [ 1 ] CVE-2024-39844 https://nvd.nist.gov/vuln/detail/CVE-2024-39844 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202409-23 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK. (CVE-2024-39844) References: - https://bugs.mageia.org/show_bug.cgi?id=33364 . MGASA-2024-0257 - Updated znc packages fix security vulnerability Publication date: 05 Jul 2024 URL: https://advisories.mageia.org/MGASA-2024-0257.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-39844 In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK. (CVE-2024-39844) References: - https://bugs.mageia.org/show_bug.cgi?id=33364 - https://www.openwall.com/lists/oss-security/2024/07/03/9 - https://www.cve.org/CVERecord?id=CVE-2024-39844 SRPMS: - 9/core/znc-1.8.2-21.1.mga9 . XYZ toolkit patches mitigate vulnerabilities linked to unauthorized access in Fedora. Urgent notice and fixes released starting August 10, 2024.. Remote Code Execution, ZNC Security, Mageia Advisory, ModTCL Patch, Security Update. . Severity: Critical. LinuxSecurity.com Team
Johannes Kuhn discovered that messages and channel names are not properly escaped in the modtcl module in ZNC, a IRC bouncer, which could result in remote code execution via specially crafted messages. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5725-1
Get the latest Linux and open source security news straight to your inbox.