Improper input validation in ZNC - CVE-2018-14055

 

Improper input validation in ZNC - CVE-2018-14055

Published: July 30, 2018 / Updated: July 30, 2018


Vulnerability identifier: #VU14122
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14055
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain elevated privileges on the target system.

The vulnerability exists due to improper validation of untrusted lines coming from the network. A remote unauthenticated attacker can supply specially crafted input to inject rogue values into znc.conf and gain elevated privileges.


Affected software

ZNC
Gentoo Linux
Debian Linux
Arch Linux
SUSE Linux
Opensuse
znc (Alpine package)

How to mitigate CVE-2018-14055

Update to version 1.7.1.

ZNC - update to 1.7.1
znc (Alpine package) - update to 1.7.1-r0

External References

Related Security Bulletins