Summary
The remote host is missing an update to znc
announced via advisory FEDORA-2009-7937.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update znc' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-7937
Insight
Update Information:
Upgrade to 0.072 of ZNC, fixes security issue in bug 513152 An users data directory traversal flaw was found in the way ZNC used to handle file upload requests via Direct Client Connection (DCC) /dcc SEND messages. A remote IRC user could issue a /dcc SEND message with a specially-crafted content (file to upload), which once accepted by a local, unsuspecting ZNC user, would overwrite relevant files in the users//downloads data directory.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-2658 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities