CVE-2010-2488: Null Pointer Dereference
Published Nov 12, 2019
·Updated
NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.
Affected Software
2 affected componentsFixes available
ZNC ZNC<0.092
debian/znc
1.8.2-2+deb11u11.8.2-3.1+deb12u11.9.1-21.10.1-1
Event History
Nov 12, 2019
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
DescriptionWeakness
Feb 17, 2026
Data Sourced
via Debian·09:51 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2010-2488?
CVE-2010-2488 is a NULL pointer dereference vulnerability in ZNC before version 0.092 caused by traffic stats when there are unauthenticated connections.
2
What is the severity of CVE-2010-2488?
The severity of CVE-2010-2488 is high with a CVSS score of 7.5.
3
Which software is affected by CVE-2010-2488?
ZNC versions before 0.092 and Debian package versions including 1.7.2-3, 1.8.2-2, and 1.8.2-3.1 are affected by CVE-2010-2488.
4
How can I fix CVE-2010-2488?
To fix CVE-2010-2488, users should upgrade to ZNC version 0.092 or later, or update the Debian package to a version that includes the fix.
5
Where can I find more information about CVE-2010-2488?
You can find more information about CVE-2010-2488 on the Debian security tracker, Red Hat access, and Debian bug report websites.