Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 323965 (CVE-2010-2448) - <net-irc/znc-0.090-r1: NULL pointer dereference with traffic stats
Summary: <net-irc/znc-0.090-r1: NULL pointer dereference with traffic stats
Alias: CVE-2010-2448
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
Whiteboard: B3 [noglsa]
: 329951 (view as bug list)
Depends on:
Reported: 2010-06-14 16:48 UTC by Alex Alexander (RETIRED)
Modified: 2010-08-14 14:59 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Alex Alexander (RETIRED) gentoo-dev 2010-06-14 16:48:40 UTC
Quoting from $URL:

"When something requested traffic statistics while there was an unauthenticated
connection to ZNC, there was a NULL pointer dereference."
Comment 1 Alex Alexander (RETIRED) gentoo-dev 2010-06-14 17:08:09 UTC
committed net-irc/znc-0.090-r1 with a patch from $URL that fixes this.
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-06-14 21:03:55 UTC
Arches, please test and mark stable:
Target keywords : "amd64 x86"
Comment 3 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-06-15 07:49:35 UTC
x86 stable
Comment 4 Markus Meier gentoo-dev 2010-06-21 20:52:04 UTC
amd64 stable, all arches done.
Comment 5 Alex Alexander (RETIRED) gentoo-dev 2010-07-27 21:05:24 UTC
All affected versions have been removed from the tree.
Comment 6 Stefan Behte (RETIRED) gentoo-dev Security 2010-08-01 12:08:17 UTC
*** Bug 329951 has been marked as a duplicate of this bug. ***
Comment 7 Stefan Behte (RETIRED) gentoo-dev Security 2010-08-01 12:09:07 UTC
Vote: no!
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2010-08-14 14:59:07 UTC
NO too, closing.