mirror of
https://github.com/znc/znc.git
synced 2026-03-28 17:42:41 +01:00
Remote attacker could execute arbitrary code embedded into the kick reason while kicking someone on a channel. To mitigate this for existing installations, simply unload the modtcl module for every user, if it's loaded. Note that only users with admin rights can load modtcl at all. While at it, also escape the channel name. Discovered by Johannes Kuhn (DasBrain) Patch by https://github.com/glguy CVE-2024-39844
18 KiB
18 KiB