Improper input validation in ZNC - CVE-2018-14055
Published: July 30, 2018 / Updated: July 30, 2018
Vulnerability details
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The vulnerability exists due to improper validation of untrusted lines coming from the network. A remote unauthenticated attacker can supply specially crafted input to inject rogue values into znc.conf and gain elevated privileges.
Affected software
Gentoo Linux
Debian Linux
Arch Linux
SUSE Linux
Opensuse
znc (Alpine package)
How to mitigate CVE-2018-14055
znc (Alpine package) - update to 1.7.1-r0