Improper input validation in ZNC - CVE-2018-14055
Published: July 30, 2018 / Updated: July 30, 2018
ZNC
Detailed vulnerability description
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The vulnerability exists due to improper validation of untrusted lines coming from the network. A remote unauthenticated attacker can supply specially crafted input to inject rogue values into znc.conf and gain elevated privileges.