USN-6990-1: znc vulnerability
USN-6990-1: znc vulnerability
4 September 2024
znc could be made to execute arbitrary code on a user’s system if they were persuaded to join a malicious server.
Releases
Ubuntu 24.04 LTS Ubuntu 22.04 LTS Ubuntu 20.04 LTS Ubuntu 18.04 ESM Ubuntu 16.04 ESM Ubuntu 14.04 ESM
Packages
znc - advanced modular IRC bouncer
Details
Johannes Kuhn (DasBrain) discovered that znc incorrectly handled
user input under certain operations. An attacker could possibly
use this issue to execute arbitrary code on a user’s system if
the user was tricked into joining a malicious server.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
znc - 1.9.0-2ubuntu0.1~esm2
Available with Ubuntu Pro