First published: Tue Mar 03 2009(Updated: )
Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZNC | =0.058 | |
ZNC | =0.056 | |
ZNC | <=0.062 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0759 is classified as a medium severity vulnerability due to the potential for privilege escalation.
To fix CVE-2009-0759, you should upgrade ZNC to version 0.066 or later, which addresses the CRLF injection vulnerabilities.
CVE-2009-0759 affects ZNC versions 0.056, 0.058, and any version up to and including 0.062.
CVE-2009-0759 can be exploited by remote authenticated users.
Exploiting CVE-2009-0759 could allow an attacker to modify the znc.conf configuration file and gain elevated privileges.