Path to this page:
Subject: CVS commit: pkgsrc/chat/znc
From: Nia Alarie
Date: 2024-08-08 00:23:46
Message id: 20240807222346.E7CDAFC74@cvs.NetBSD.org
Log Message:
znc: Update to 1.9.1
* This is a security release to fix CVE-2024-39844: remote code execution \
vulnerability in modtcl.
* To mitigate this for existing installations, simply unload the modtcl \
module for every user, if it's loaded. Note that only users with admin rights \
can load modtcl at all.
* Thanks to Johannes Kuhn (DasBrain) for reporting, to glguy for the patch, \
and to multiple IRC network operators for help with mitigating this on server \
side before disclosure.
* Improve tooltips in webadmin.
Files: