CVE-2010-2448

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
zncznc
𝑥
≤ 0.090
zncznc
0.034
zncznc
0.041
zncznc
0.043
zncznc
0.044
zncznc
0.045
zncznc
0.047
zncznc
0.050
zncznc
0.052
zncznc
0.054
zncznc
0.056
zncznc
0.058
zncznc
0.060
zncznc
0.062
zncznc
0.064
zncznc
0.066
zncznc
0.068
zncznc
0.070
zncznc
0.072
zncznc
0.074
zncznc
0.076
zncznc
0.078
zncznc
0.080
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
znc
quantal
Fixed 0.090-2
released
precise
Fixed 0.090-2
released
oneiric
Fixed 0.090-2
released
natty
Fixed 0.090-2
released
maverick
Fixed 0.090-2
released
lucid
Fixed 0.078-1ubuntu0.1
released
karmic
ignored
jaunty
ignored
hardy
ignored
dapper
dne