#VU97707 Input validation error in ZNC - CVE-2024-39844
Published: September 25, 2024 / Updated: November 22, 2024
ZNC
ZNC
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in modtcl when processing the reason to kick a user from the channel. A remote user can pass specially crafted input to the application and execute arbitrary code on the server.