Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 471738 (CVE-2013-2130) - <net-irc/znc-1.0-r2 : Multiple NULL Pointer Dereference Vulnerabilities (CVE-2013-2130)
Summary: <net-irc/znc-1.0-r2 : Multiple NULL Pointer Dereference Vulnerabilities (CVE-...
Status: RESOLVED FIXED
Alias: CVE-2013-2130
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/53450/
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-29 18:57 UTC by Agostino Sarubbo
Modified: 2014-12-19 01:08 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-05-29 18:57:35 UTC
From ${URL} :

Description
Multiple vulnerabilities have been reported in ZNC, which can be 
exploited by malicious users to cause a DoS (Denial of Service).

The vulnerabilities are caused due to errors when handling the 
"editnetwork", "editchan", "addchan", and "delchan" page requests and 
can be exploited to cause a NULL pointer dereference.

The vulnerabilities are reported in version 1.0.


Solution
Fixed in the git repository.

Provided and/or discovered by
The vendor credits Simone "ChauffeR" Esposito.

Original Advisory
ZNC:
https://github.com/znc/znc/commit/2bd410ee5570cea127233f1133ea22f25174eb28


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Alex Alexander (RETIRED) gentoo-dev 2013-05-31 12:29:22 UTC
The issue is fixed in =net-irc/znc-1.0-r2

which is ready for stabilization.
Comment 2 Elijah "Armageddon" El Lazkani (amd64 AT) 2013-06-02 14:59:30 UTC
amd64: pass
Comment 3 Tomáš "tpruzina" Pružina (amd64 [ex]AT) 2013-06-03 11:22:58 UTC
amd64: ok (builds, runs)
Comment 4 Agostino Sarubbo gentoo-dev 2013-06-04 12:29:08 UTC
x86 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-06-04 12:31:38 UTC
amd64 stable
Comment 6 Sergey Popov gentoo-dev 2013-09-04 06:18:56 UTC
GLSA vote: yes
Comment 7 Yury German Gentoo Infrastructure gentoo-dev 2014-06-19 02:40:54 UTC
GLSA Vote: Yes
Created a New GLSA request.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2014-08-19 22:57:10 UTC
CVE-2013-2130 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2130):
  ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL
  pointer reference and crash) via a crafted request to the (1) editnetwork,
  (2) editchan, (3) addchan, or (4) delchan page in modules/webadmin.cpp.
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2014-12-19 01:08:51 UTC
This issue was resolved and addressed in
 GLSA 201412-31 at http://security.gentoo.org/glsa/glsa-201412-31.xml
by GLSA coordinator Sean Amoss (ackle).