Path traversal in ZNC - CVE-2018-14056

 

Path traversal in ZNC - CVE-2018-14056

Published: July 30, 2018


Vulnerability identifier: #VU14123
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14056
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to path traversal flaw when handling malicious input passed via ../ in a web skin name. A remote unauthenticated attacker can supply specially crafted input to  access files outside of the intended skins directories.


Affected software

ZNC
Gentoo Linux
Debian Linux
Arch Linux
SUSE Linux
Opensuse
znc (Alpine package)

How to mitigate CVE-2018-14056

Update to version 1.7.1.

ZNC - update to 1.7.1
znc (Alpine package) - update to 1.7.1-r0

External References

Related Security Bulletins