CVE-2013-2130
EPSS 1.1%
Description
ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) editnetwork, (2) editchan, (3) addchan, or (4) delchan page in modules/webadmin.cpp.
How to fix CVE-2013-2130
To remediate CVE-2013-2130, upgrade the affected package to a fixed version below.
- Debian/znc—upgrade to 1.0-5 or later
Is CVE-2013-2130 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.0-5