Bug#744712: znc: ZNC can be crashed by any user if webadmin is loaded

2014-04-13 Thread Richard Schwab
Package: znc Version: 1.2-3 Severity: grave Tags: security patch Justification: renders package unusable Details: https://github.com/znc/znc/issues/528 Patch: https://github.com/znc/znc/commit/5e6e3be32acfeadeaf1fb3bb17bada08aec6432f -- System Information: Debian Release: 7.4 APT prefers

Bug#744712: znc: ZNC can be crashed by any user if webadmin is loaded

2014-04-13 Thread Uli Schlachter
Hi, the bug was introduced in the following commit: https://github.com/znc/znc/commit/997023ea9de8fcc4ab68f0139015e1b7dba3b8a9 This is from 2005. Or put differently, everything this release is affected: $ git describe --contains 997023ea9de8fcc4ab68f0139015e1b7dba3b8a9 znc-0.043~72 Yay, Uli