Back to Database
Status published
High
CVE-2009-2658
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers...
Vulnerability Description
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2658
Credits & Attribution
No credits recorded in the NVD database.
References
- http://en.znc.in/w/index.php?title=ZNC&oldid=3209#WARNING
- http://www.openwall.com/lists/oss-security/2009/07/21/5
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00965.html
- http://znc.svn.sourceforge.net/viewvc/znc?view=rev&sortby=rev&sortdir=down&revision=1570
- http://en.znc.in/wiki/ChangeLog/0.072
- http://secunia.com/advisories/35916
- http://www.debian.org/security/2009/dsa-1848
More from znc
View All →CVE-2020-29577
The official znc docker images before 1.7.1-slim contain a blank...
Critical
9.8
CVE-2020-13775
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger...
Medium
6.5
CVE-2019-9917
ZNC before 1.7.3-rc1 allows an existing remote user to cause...
Medium
6.5
CVE-2019-12816
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users...
High
8.8
CVE-2018-14056
ZNC before 1.7.1-rc1 is prone to a path traversal flaw...
Medium
5.3
Affected Vendor
Affected Software
znc
Vulnerable Versions:
0.044, 0.045, 0.047, 0.052, 0.054, 0.056, 0.058, 0.060, 0.062, 0.064, 0.066, 0.068, 0.070
Timeline
Official Publish:
August 4th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.