Alexey Sokolov
8cbf8d6281
Fix RCE vulnerability in modtcl
...
Remote attacker could execute arbitrary code embedded into the kick
reason while kicking someone on a channel.
To mitigate this for existing installations, simply unload the modtcl
module for every user, if it's loaded.
Note that only users with admin rights can load modtcl at all.
While at it, also escape the channel name.
Discovered by Johannes Kuhn (DasBrain)
Patch by https://github.com/glguy
CVE-2024-39844
2024-07-01 10:27:49 +01:00
..
2024-04-10 22:56:29 -07:00
2024-01-14 12:11:00 +00:00
2024-01-14 11:12:32 +00:00
2023-12-31 21:09:25 +01:00
2024-02-26 00:33:25 +00:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2024-02-10 00:18:11 +00:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2024-01-14 12:11:00 +00:00
2024-01-14 11:12:32 +00:00
2024-07-01 10:27:49 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2023-12-31 21:09:25 +01:00
2024-04-10 22:38:23 -07:00