6.5
CVSSv2

CVE-2019-12816

Published: 15/06/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Modules.cpp in ZNC prior to 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

znc znc

Vendor Advisories

znc could be made to crash or run programs as an administrator if it opened a specially crafted file ...
Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917) For the stable distribution (stretch), these problems have been fixed in version 165-1+deb9u2 We recommend that you upgrade your znc packages For the detailed security ...