First published: Tue Apr 08 2014(Updated: )
The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of service (crash) via a crafted DCC RESUME request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ZNC znc-msvc Windows | =0.200 | |
ZNC znc-msvc Windows | =0.202 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0033 is classified as a denial of service vulnerability.
To fix CVE-2012-0033, upgrade ZNC to version 0.203 or later.
CVE-2012-0033 affects ZNC versions 0.200 and 0.202.
CVE-2012-0033 is associated with remote attackers causing a denial of service via a crafted DCC RESUME request.
The vulnerability in CVE-2012-0033 is found in the CBounceDCCMod::OnPrivCTCP function in the bouncedcc module.