CVE-2013-2130: Medium severity ZNC ZNC vulnerability
Published Jun 5, 2014
·Updated
ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) editnetwork, (2) editchan, (3) addchan, or (4) delchan page in modules/webadmin.cpp.
Affected Software
1 affected component
ZNC ZNC=1.0
Remediation
Event History
Jun 5, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:55 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-2130?
CVE-2013-2130 is classified as a denial of service vulnerability which can lead to a crash of the ZNC application.
2
How do I fix CVE-2013-2130?
To fix CVE-2013-2130, you should upgrade ZNC to a version later than 1.0 where this issue has been resolved.
3
Who is affected by CVE-2013-2130?
CVE-2013-2130 affects remote authenticated users of ZNC version 1.0.
4
What types of requests can exploit CVE-2013-2130?
Requests made to the editnetwork, editchan, addchan, or delchan pages can exploit CVE-2013-2130.
5
What are the potential impacts of CVE-2013-2130?
The potential impact of CVE-2013-2130 is a denial of service leading to the crashing of the ZNC server.