2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2010-2448" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2010-07-12T17:30:01.377" ,
2024-11-22 11:14:00 +00:00
"lastModified" : "2024-11-21T01:16:41.007" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell."
} ,
{
"lang" : "es" ,
"value" : "znc.cpp en ZNC antes de v0.092 permite a los usuarios remotos autenticados causar una denegaci\u00f3n de servicio (caida de la aplicaci\u00f3n) al solicitar las estad\u00edsticas de tr\u00e1fico cuando hay una conexi\u00f3n activa no autenticada, lo que desencadena una referencia a un puntero NULL, como se ha demostrado usando (1) un enlace de tr\u00e1fico en la p\u00e1ginas web de administraci\u00f3n o (2) el comando traffic en la shell /znc."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P" ,
2024-11-22 11:14:00 +00:00
"baseScore" : 3.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-22 11:14:00 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 6.8 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "0.090" ,
"matchCriteriaId" : "3A23F341-516C-482C-814F-560E7E346F4C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.034:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CAABF9A2-241D-40DC-A7D9-6864AC3CC6AE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.041:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4B15AC84-9EC6-4558-A445-F4085659B4F7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.043:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9CE21062-0BFC-476A-B616-15B7DF79A895"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.044:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0C012D55-9039-4D68-9CA0-5624ADEF583F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.045:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0C185E34-735D-4839-8C05-B46CE7028765"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.047:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "60AEE9F9-78B7-40B4-B28A-1B8F068CA953"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.050:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "453B05F9-C630-4329-BE91-8EEA6B0C47D9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.052:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4AECFB9F-9630-438F-9BE4-E4A44A5023FB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.054:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CA564C01-2757-479C-9E33-2D7F0890C61C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.056:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1BFE27D3-487B-41A2-A6CE-AA36E07506BE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.058:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "13E7CC41-1923-4295-8AFC-8D295FDD9C5D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.060:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3C2127D9-936F-4E71-BB78-02DE61FF44C6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.062:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "89151E35-63D2-440E-AD2F-A2BAECA6884B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.064:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "952BC3B5-4D07-4C61-B3FE-650FBC699B8F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.066:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9983141A-3B1F-41EE-809A-0F435EC067C2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.068:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6A505A45-4404-4E0E-97AD-69D9C5D280DC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.070:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AB8B51F-4FD7-463B-9E8B-6846E7E690A5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.072:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0BCA1336-CE79-4193-89AA-0AA9C399AF7D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.074:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "41FA061E-155D-4F9F-BFE0-956AEAF977D3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.076:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5FCDF1C4-C831-4BC4-91AA-9DF027E9FC75"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.078:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6C19FD33-9192-4EC2-B68F-4B49D859E627"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:znc:znc:0.080:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3209D93B-9DD2-49CE-9C3C-AD8573E4F1DA"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584929" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043000.html" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043043.html" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043044.html" ,
"source" : "cve@mitre.org"
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/40523" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://sourceforge.net/projects/znc/files/znc/0.092/znc-0.092-changelog.txt/view" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.debian.org/security/2010/dsa-2069" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/bid/40982" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2010/1775" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://znc.svn.sourceforge.net/viewvc/znc/trunk/znc.cpp?r1=2025&r2=2026&pathrev=2026" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://znc.svn.sourceforge.net/viewvc/znc?revision=2026&view=revision" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch"
]
2024-11-22 11:14:00 +00:00
} ,
{
"url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584929" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043000.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043043.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043044.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://secunia.com/advisories/40523" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://sourceforge.net/projects/znc/files/znc/0.092/znc-0.092-changelog.txt/view" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.debian.org/security/2010/dsa-2069" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/40982" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2010/1775" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://znc.svn.sourceforge.net/viewvc/znc/trunk/znc.cpp?r1=2025&r2=2026&pathrev=2026" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://znc.svn.sourceforge.net/viewvc/znc?revision=2026&view=revision" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2023-04-24 12:24:31 +02:00
}
2024-11-22 11:14:00 +00:00
] ,
"evaluatorComment" : "Per: http://cwe.mitre.org/data/definitions/476.html\r\n\r\n'CWE-476: NULL Pointer Dereference'"
2023-04-24 12:24:31 +02:00
}