Path traversal in ZNC - CVE-2018-14056
Published: July 30, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to path traversal flaw when handling malicious input passed via ../ in a web skin name. A remote unauthenticated attacker can supply specially crafted input to access files outside of the intended skins directories.
Affected software
Gentoo Linux
Debian Linux
Arch Linux
SUSE Linux
Opensuse
znc (Alpine package)
How to mitigate CVE-2018-14056
znc (Alpine package) - update to 1.7.1-r0