6.5
CVSSv3

CVE-2019-9917

Published: 27/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

ZNC prior to 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

znc znc

canonical ubuntu linux 18.10

fedoraproject fedora 28

fedoraproject fedora 29

fedoraproject fedora 30

Vendor Advisories

Debian Bug report logs - #925285 znc: CVE-2019-9917: crash on invalid encoding Package: src:znc; Maintainer for src:znc is Patrick Matthäi <pmatthaei@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Mar 2019 13:18:02 UTC Severity: important Tags: security, upstream Found in versions ...
ZNC could be made to crash or run programs if it received specially crafted network traffic ...
Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917) For the stable distribution (stretch), these problems have been fixed in version 165-1+deb9u2 We recommend that you upgrade your znc packages For the detailed security ...