Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1735-1 | New znc packages fix privilege escalation |
EUVD |
EUVD-2009-0759 | Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T04:48:51.664Z
Reserved: 2009-03-03T00:00:00
Link: CVE-2009-0759
No data.
Status : Deferred
Published: 2009-03-03T16:30:05.327
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-0759
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD