ZNC 0.202: vulnerability in bouncedcc module

Bug #913836 reported by Thomas Ward
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
znc (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Vulnerability exists in bouncedcc module. Vulnerability will cause a crash when DCC RESUME is received.

Upstream fix:
https://github.com/znc/znc/commit/11508aa72efab4fad0dbd8292b9614d9371b20a9

Patch (from Debian):
http://patch-tracker.debian.org/patch/series/view/znc/0.202-2/01-fix-bouncedcc-dos.diff

Debian patch may need to be tweaked for Ubuntu, however I cannot confirm this (patch attached to bug anyways)

PACKAGES NEEDING FIXES:
Precise Universe
Oneiric Backports
Natty Backports (does not build, due to a bug blocking it)

Revision history for this message
Thomas Ward (teward) wrote :
visibility: private → public
description: updated
security vulnerability: yes → no
Revision history for this message
Thomas Ward (teward) wrote :

Fixed in debian: Version: 0.202-2.

Sync requested from Debian Sid to Precise in Bug #914026.

Changed in znc (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.