DSA-4463-1 znc -- security update

Related Vulnerabilities: CVE-2019-9917   CVE-2019-12816  

Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917). For the stable distribution (stretch), these problems have been fixed in version 1.6.5-1+deb9u2. We recommend that you upgrade your znc packages. For the detailed security status of znc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/znc

Debian Security Advisory

DSA-4463-1 znc -- security update

Date Reported:
14 Jun 2019
Affected Packages:
znc
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 925285.
In Mitre's CVE dictionary: CVE-2019-9917, CVE-2019-12816.
More information:

Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917).

For the stable distribution (stretch), these problems have been fixed in version 1.6.5-1+deb9u2.

We recommend that you upgrade your znc packages.

For the detailed security status of znc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/znc