Bug 2298802
Summary: | CVE-2024-39844 znc: remote code execution via modtcl [epel-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora EPEL | Reporter: | Robb Gatica <rgatica> |
Component: | znc | Assignee: | Neil Hanlon <neil> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | epel8 | CC: | cmm11, nb, rcallicotte |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | {"flaws": ["55daf565-545c-416e-8aeb-05828313adc8"]} | ||
Fixed In Version: | znc-1.8.2-16.el8 znc-1.8.2-16.el9 | Doc Type: | No Doc Update |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2025-05-21 00:32:56 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 2295622 |
Description
Robb Gatica
2024-07-18 22:50:30 UTC
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component. This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component. Hello is it possible to get version 1.9.1 packages for F40? As it's been now over 2 months that znc-modtcl has had this RCE. I have opened PRs for EPEL8/9. These contain the backported fix for CVE-2024-39844. Please see below: https://src.fedoraproject.org/rpms/znc/pull-request/10 https://src.fedoraproject.org/rpms/znc/pull-request/9 FEDORA-EPEL-2025-f3a22dfde8 (znc-1.8.2-16.el9) has been submitted as an update to Fedora EPEL 9. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-f3a22dfde8 FEDORA-EPEL-2025-ad4c7abaa9 (znc-1.8.2-16.el8) has been submitted as an update to Fedora EPEL 8. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-ad4c7abaa9 FEDORA-EPEL-2025-ad4c7abaa9 has been pushed to the Fedora EPEL 8 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-ad4c7abaa9 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-EPEL-2025-f3a22dfde8 has been pushed to the Fedora EPEL 9 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-f3a22dfde8 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-EPEL-2025-ad4c7abaa9 (znc-1.8.2-16.el8) has been pushed to the Fedora EPEL 8 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-EPEL-2025-f3a22dfde8 (znc-1.8.2-16.el9) has been pushed to the Fedora EPEL 9 stable repository. If problem still persists, please make note of it in this bug report. |