CVE-2024-39844: ZNC modtcl RCE
Published Jul 3, 2024
·Updated
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
Affected Software
1 affected componentFixes available
debian/znc
1.8.2-2+deb11u11.8.2-3.1+deb12u11.9.1-1
Remediation
Event History
Jul 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Sep 16, 2024
Data Sourced
via Ubuntu·08:20 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39844?
CVE-2024-39844 has been identified as a critical vulnerability allowing for remote code execution in ZNC before version 1.9.1.
2
How do I fix CVE-2024-39844?
To mitigate CVE-2024-39844, update ZNC to version 1.9.1 or later.
3
What versions of ZNC are affected by CVE-2024-39844?
CVE-2024-39844 affects ZNC versions prior to 1.9.1, including all versions before that release.
4
What component of ZNC is vulnerable in CVE-2024-39844?
The vulnerability in CVE-2024-39844 specifically affects the modtcl component of ZNC.
5
How can remote code execution occur in CVE-2024-39844?
Remote code execution in CVE-2024-39844 can occur via the KICK command in modtcl.