USN-6990-1: znc vulnerability
4 September 2024
znc could be made to execute arbitrary code on a user's system if they were persuaded to join a malicious server.
Releases
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 ESM
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM
Packages
- znc - advanced modular IRC bouncer
Details
Johannes Kuhn (DasBrain) discovered that znc incorrectly handled
user input under certain operations. An attacker could possibly
use this issue to execute arbitrary code on a user's system if
the user was tricked into joining a malicious server.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
-
znc
-
1.9.0-2ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-dev
-
1.9.0-2ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-perl
-
1.9.0-2ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-python
-
1.9.0-2ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-tcl
-
1.9.0-2ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 22.04
-
znc
-
1.8.2-2ubuntu0.1
-
znc-dev
-
1.8.2-2ubuntu0.1
-
znc-perl
-
1.8.2-2ubuntu0.1
-
znc-python
-
1.8.2-2ubuntu0.1
-
znc-tcl
-
1.8.2-2ubuntu0.1
Ubuntu 20.04
-
znc
-
1.7.5-4ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-dev
-
1.7.5-4ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-perl
-
1.7.5-4ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-python
-
1.7.5-4ubuntu0.1~esm2
Available with Ubuntu Pro
-
znc-tcl
-
1.7.5-4ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 18.04
-
znc
-
1.6.6-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-dev
-
1.6.6-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-perl
-
1.6.6-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-python
-
1.6.6-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-tcl
-
1.6.6-1ubuntu0.2+esm2
Available with Ubuntu Pro
Ubuntu 16.04
-
znc
-
1.6.3-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-dev
-
1.6.3-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-perl
-
1.6.3-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-python
-
1.6.3-1ubuntu0.2+esm2
Available with Ubuntu Pro
-
znc-tcl
-
1.6.3-1ubuntu0.2+esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
znc
-
1.2-3ubuntu0.1+esm3
Available with Ubuntu Pro
-
znc-dev
-
1.2-3ubuntu0.1+esm3
Available with Ubuntu Pro
-
znc-perl
-
1.2-3ubuntu0.1+esm3
Available with Ubuntu Pro
-
znc-python
-
1.2-3ubuntu0.1+esm3
Available with Ubuntu Pro
-
znc-tcl
-
1.2-3ubuntu0.1+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.