ZNC: Privilege escalation A vulnerability in ZNC allows users to escalate privileges. znc 2019-08-15 2019-08-15 688152 remote 1.7.4_rc1 1.7.4_rc1

ZNC is an advanced IRC bouncer.

It was discovered that ZNC’s “Modules.cpp” allows remote authenticated non-admin users to escalate privileges.

A remote authenticated attacker could escalate privileges and subsequently execute arbitrary code or conduct a Denial of Service attack.

There is no known workaround at this time.

All ZNC users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-irc/znc-1.7.4_rc1"
CVE-2019-12816 b-man b-man