CVE-2010-2448

EUVD-2010-2457
znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
zncznc
𝑥
≤ 0.090
zncznc
0.034
zncznc
0.041
zncznc
0.043
zncznc
0.044
zncznc
0.045
zncznc
0.047
zncznc
0.050
zncznc
0.052
zncznc
0.054
zncznc
0.056
zncznc
0.058
zncznc
0.060
zncznc
0.062
zncznc
0.064
zncznc
0.066
zncznc
0.068
zncznc
0.070
zncznc
0.072
zncznc
0.074
zncznc
0.076
zncznc
0.078
zncznc
0.080
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
znc
dapper
dne
hardy
ignored
jaunty
ignored
karmic
ignored
lucid
Fixed 0.078-1ubuntu0.1
released
maverick
Fixed 0.090-2
released
natty
Fixed 0.090-2
released
oneiric
Fixed 0.090-2
released
precise
Fixed 0.090-2
released
quantal
Fixed 0.090-2
released