CVE-2018-14055: Input Validation
Published Jul 15, 2018
·Updated
ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.
Affected Software
3 affected componentsFixes available
debian/znc
1.7.2-31.8.2-21.8.2-3.1
ZNC ZNC<=1.7.0
Debian Debian Linux=9.0
Remediation
Event History
Jul 15, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-14055.
2
What is the severity level of CVE-2018-14055?
The severity level of CVE-2018-14055 is medium (6.5).
3
How does CVE-2018-14055 affect ZNC before version 1.7.1-rc1?
CVE-2018-14055 allows a non-admin user to escalate their privilege and inject rogue values into znc.conf.
4
Which software versions are affected by CVE-2018-14055?
ZNC versions up to and including 1.7.0 are affected by CVE-2018-14055.
5
How can I fix CVE-2018-14055?
CVE-2018-14055 can be fixed by updating to ZNC version 1.7.1-rc1 or later.