ZNC: Directory traversal A directory traversal was found in ZNC, allowing for overwriting of arbitrary files. znc 2009-09-13 2009-09-13 278684 remote 0.074 0.074

ZNC is an advanced IRC bouncer.

The vendor reported a directory traversal vulnerability when processing DCC SEND requests.

A remote, authenticated user could send a specially crafted DCC SEND request to overwrite arbitrary files with the privileges of the user running ZNC, and possibly cause the execution of arbitrary code e.g. by uploading a malicious ZNC module.

There is no known workaround at this time.

All ZNC users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-irc/znc-0.074"
CVE-2009-2658 keytoaster keytoaster keytoaster