Vulnerability Name:

CVE-2010-2448 (CCN-59613)

Assigned:2010-06-21
Published:2010-06-21
Updated:2010-07-12
Summary:znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.
Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P)
2.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584929

Source: MITRE
Type: CNA
CVE-2010-2448

Source: CCN
Type: ZNC Web site
ZNC

Source: FEDORA
Type: UNKNOWN
FEDORA-2010-10042

Source: FEDORA
Type: UNKNOWN
FEDORA-2010-10078

Source: FEDORA
Type: UNKNOWN
FEDORA-2010-10082

Source: SECUNIA
Type: Vendor Advisory
40523

Source: CONFIRM
Type: UNKNOWN
http://sourceforge.net/projects/znc/files/znc/0.092/znc-0.092-changelog.txt/view

Source: DEBIAN
Type: UNKNOWN
DSA-2069

Source: DEBIAN
Type: DSA-2069
znc -- denial of service

Source: CCN
Type: OSVDB ID: 66236
Debian ZNC znc.cpp Traffic Statistics Processing NULL Dereference Remote DoS

Source: BID
Type: UNKNOWN
40982

Source: CCN
Type: BID-40982
ZNC NULL Pointer Dereference Denial Of Service Vulnerability

Source: VUPEN
Type: Vendor Advisory
ADV-2010-1775

Source: MISC
Type: UNKNOWN
http://znc.svn.sourceforge.net/viewvc/znc/trunk/znc.cpp?r1=2025&r2=2026&pathrev=2026

Source: CONFIRM
Type: Patch
http://znc.svn.sourceforge.net/viewvc/znc?revision=2026&view=revision

Source: CCN
Type: Red Hat Bugzilla Bug 603915
znc: NULL pointer dereference flaw leads to segfault under certain conditions

Source: XF
Type: UNKNOWN
znc-traffic-dos(59613)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:znc:znc:0.034:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.041:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.043:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.044:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.045:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.047:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.050:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.052:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.054:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.056:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.058:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.060:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.062:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.064:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.066:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.068:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.070:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.072:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.074:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.076:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.078:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.080:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:*:*:*:*:*:*:*:* (Version <= 0.090)

  • Configuration CCN 1:
  • cpe:/a:znc:znc:0.064:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.062:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.060:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.058:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.056:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.054:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.052:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.050:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.047:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.045:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.044:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.041:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.034:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.066:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.090:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.080:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.078:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.076:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.074:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.072:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.070:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.068:*:*:*:*:*:*:*
  • OR cpe:/a:znc:znc:0.043:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:11828
    P
    DSA-2069 znc -- denial of service
    2014-06-23
    oval:org.mitre.oval:def:13565
    P
    DSA-2069-1 znc -- denial of service
    2014-06-23
    oval:com.ubuntu.precise:def:20102448000
    V
    CVE-2010-2448 on Ubuntu 12.04 LTS (precise) - medium.
    2010-07-12
    oval:org.debian:def:2069
    V
    denial of service
    2010-07-11
    BACK
    znc znc 0.034
    znc znc 0.041
    znc znc 0.043
    znc znc 0.044
    znc znc 0.045
    znc znc 0.047
    znc znc 0.050
    znc znc 0.052
    znc znc 0.054
    znc znc 0.056
    znc znc 0.058
    znc znc 0.060
    znc znc 0.062
    znc znc 0.064
    znc znc 0.066
    znc znc 0.068
    znc znc 0.070
    znc znc 0.072
    znc znc 0.074
    znc znc 0.076
    znc znc 0.078
    znc znc 0.080
    znc znc *
    znc znc 0.064
    znc znc 0.062
    znc znc 0.060
    znc znc 0.058
    znc znc 0.056
    znc znc 0.054
    znc znc 0.052
    znc znc 0.050
    znc znc 0.047
    znc znc 0.045
    znc znc 0.044
    znc znc 0.041
    znc znc 0.034
    znc znc 0.066
    znc znc 0.090
    znc znc 0.080
    znc znc 0.078
    znc znc 0.076
    znc znc 0.074
    znc znc 0.072
    znc znc 0.070
    znc znc 0.068
    znc znc 0.043
    debian debian linux 5.0