Candidate: CVE-2010-2448 PublicDate: 2010-07-12 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2448 http://www.openwall.com/lists/oss-security/2010/07/14/1 Description: znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell. Ubuntu-Description: Notes: sbeattie> debian's CVE tracker for some reason references gitolite with this CVE; I think it's an editing mistake. mdeslaur> this is actually a typo. CVE-2010-2488 is the actual CVE number. Bugs: https://bugs.launchpad.net/ubuntu/+source/znc/+bug/1090195 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584929 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_znc: upstream: http://znc.svn.sourceforge.net/viewvc/znc/trunk/znc.cpp?r1=2025&r2=2026&pathrev=2026 upstream_znc: released (0.092) dapper_znc: DNE hardy_znc: ignored (reached end-of-life) jaunty_znc: ignored (reached end-of-life) karmic_znc: ignored (reached end-of-life) lucid_znc: released (0.078-1ubuntu0.1) maverick_znc: released (0.090-2) natty_znc: released (0.090-2) oneiric_znc: released (0.090-2) precise_znc: released (0.090-2) quantal_znc: released (0.090-2) devel_znc: released (0.090-2)