CVE-2019-9917: Input Validation
Published Mar 22, 2019
·Updated
Last updated 26 August 2025
Other sources
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
— Launchpad
Affected Software
7 affected componentsFixes available
debian/znc<=1.7.2-1, <=1.6.5-1+deb9u1
ZNC ZNC<=1.7.2
Canonical Ubuntu Linux=18.10
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Fedoraproject Fedora=30
debian/znc
1.8.2-2+deb11u11.8.2-3.1+deb12u11.9.1-21.10.1-1
Remediation
Event History
Mar 27, 2019
CVE Published
via MITRE·05:41 AM
Data Sourced
via MITRE·05:41 AM
Description
Feb 23, 2026
Data Sourced
via Ubuntu·05:46 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:46 PM
DescriptionAffected Software
Data Sourced
via Launchpad·05:46 PM
Description
Frequently Asked Questions
1
What is CVE-2019-9917?
CVE-2019-9917 is a vulnerability in ZNC before 1.7.3-rc1 that allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
2
How can the CVE-2019-9917 vulnerability be exploited?
The CVE-2019-9917 vulnerability can be exploited by a remote user sending invalid encoding, causing the system to crash.
3
What is the severity of CVE-2019-9917?
The severity of CVE-2019-9917 is rated as high with a CVSS score of 6.5.
4
Which software versions are affected by CVE-2019-9917?
ZNC versions before 1.7.3-rc1 are affected by CVE-2019-9917.
5
How can I fix the CVE-2019-9917 vulnerability?
To fix the CVE-2019-9917 vulnerability, update ZNC to version 1.7.3-rc1 or later.