CVE-2012-0033: Medium severity ZNC Znc-msvc vulnerability
Published Apr 8, 2014
·Updated
The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of service (crash) via a crafted DCC RESUME request.
Affected Software
2 affected components
ZNC Znc-msvc=0.200
ZNC Znc-msvc=0.202
Event History
Apr 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:22 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-0033?
CVE-2012-0033 is classified as a denial of service vulnerability.
2
How do I fix CVE-2012-0033?
To fix CVE-2012-0033, upgrade ZNC to version 0.203 or later.
3
What versions of ZNC are affected by CVE-2012-0033?
CVE-2012-0033 affects ZNC versions 0.200 and 0.202.
4
What type of attack is associated with CVE-2012-0033?
CVE-2012-0033 is associated with remote attackers causing a denial of service via a crafted DCC RESUME request.
5
What component of ZNC is vulnerable in CVE-2012-0033?
The vulnerability in CVE-2012-0033 is found in the CBounceDCCMod::OnPrivCTCP function in the bouncedcc module.