| Summary: | znc new security issue CVE-2013-2130 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | geiger.david68210, sysadmin-bugs, tmb |
| Version: | 3 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/563960/ | ||
| Whiteboard: | has_procedure mga3-64-ok mga3-32-ok | ||
| Source RPM: | znc-1.0-2.mga3.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2013-08-19 23:30:16 CEST
Testing complete mga3 64 No PoC's but the CVE is to do with the webadmin interface so checking that works. $ znc --makeconf answer all the questions it asks and allow it to start. created with user/password znctest/znctest Connected to the running znc instance with an irc client with the server as localhost and the port znc was configured to listen on (I used 3456) and the server password set to znctest/freenode:znctest Logged into the web interface at https://localhost:3456 and made sure it was still able to edit channels and networks. Killed znc with 'killall znc' It does seem to be missing a systemd service so i'll create a new bug for that. Whiteboard:
(none) =>
has_procedure mga3-64-ok Testing complete mga3_32, ok for me nothing to report. same as comment 1 CC:
(none) =>
geiger.david68210 Validating. Advisory from comment 0 uploaded. Could sysadmin please push from 3 core/updates_testing to updates Thanks! Keywords:
(none) =>
validated_update Update pushed: http://advisories.mageia.org/MGASA-2013-0257.html Status:
NEW =>
RESOLVED |