CVE-2009-2658: Path Traversal
Published Aug 4, 2009
·Updated
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
Affected Software
13 affected components
ZNC ZNC=0.044
ZNC ZNC=0.062
ZNC ZNC=0.045
ZNC ZNC=0.052
ZNC ZNC=0.058
ZNC ZNC=0.056
ZNC ZNC=0.070
ZNC ZNC=0.064
ZNC ZNC=0.068
ZNC ZNC=0.054
ZNC ZNC=0.060
ZNC ZNC=0.047
ZNC ZNC=0.066
Remediation
Patch Available
Event History
Aug 4, 2009
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2658?
CVE-2009-2658 has a severity rating classified as important due to its potential to overwrite arbitrary files.
2
How do I fix CVE-2009-2658?
To mitigate CVE-2009-2658, upgrade ZNC to version 0.072 or later.
3
Which versions of ZNC are affected by CVE-2009-2658?
CVE-2009-2658 affects all ZNC versions prior to 0.072, including versions 0.044 through 0.070.
4
What kind of attack is associated with CVE-2009-2658?
CVE-2009-2658 enables remote attackers to exploit a directory traversal vulnerability through a crafted DCC SEND request.
5
What are the potential risks of CVE-2009-2658?
The risks associated with CVE-2009-2658 include unauthorized file overwriting and potential system compromise.