High severity8.8NVD Advisory· Published Jun 15, 2019· Updated Jun 17, 2026
CVE-2019-12816
CVE-2019-12816
Description
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- ZNC/ZNCdescription
- osv-coords5 versionspkg:rpm/opensuse/znc&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/znc&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/znc&distro=openSUSE%20Tumbleweedpkg:rpm/suse/znc&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/znc&distro=SUSE%20Package%20Hub%2015%20SP1
< 1.7.4-bp150.2.6.1+ 4 more
- (no CPE)range: < 1.7.4-bp150.2.6.1
- (no CPE)range: < 1.7.4-bp150.2.6.1
- (no CPE)range: < 1.8.2-1.11
- (no CPE)range: < 1.7.4-bp150.2.6.1
- (no CPE)range: < 1.7.4-bp151.4.3.1
Patches
Vulnerability mechanics
References
11- github.com/znc/znc/commit/8de9e376ce531fe7f3c8b0aa4876d15b479b7311nvdPatchThird Party Advisory
- github.com/znc/znc/compare/be1b6bc...d1997d6nvdPatchThird Party Advisory
- seclists.org/bugtraq/2019/Jun/23nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-07/msg00037.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00018.htmlnvd
- lists.debian.org/debian-lts-announce/2019/06/msg00017.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4O24TQOB73X57GACLZVMRVUK4UKHLE5G/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NHR6OD52FQAG5ZPZ42NJM2T765C3V2XC/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEESIGRNFLZUWXZPDGXAZ7JZTHYBDJ7G/nvd
- security.gentoo.org/glsa/201908-15nvd
- usn.ubuntu.com/4044-1/nvd
News mentions
0No linked articles in our index yet.