CVE-2018-14056: Path Traversal
Published Jul 15, 2018
·Updated
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.
Affected Software
3 affected componentsFixes available
debian/znc
1.7.2-31.8.2-21.8.2-3.1
ZNC ZNC<=1.7.0
Debian Debian Linux=9.0
Remediation
Event History
Jul 15, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-14056?
CVE-2018-14056 is a vulnerability in ZNC before 1.7.1-rc1 that allows path traversal via ../ in a web skin name to access files outside the intended directories.
2
How severe is CVE-2018-14056?
CVE-2018-14056 has a severity rating of medium, with a CVSS score of 5.3.
3
Which software versions are affected by CVE-2018-14056?
ZNC versions before 1.7.1-rc1 are affected by CVE-2018-14056.
4
How can I fix CVE-2018-14056?
To fix CVE-2018-14056, update ZNC to version 1.7.1-rc1 or later.
5
Where can I find more information about CVE-2018-14056?
You can find more information about CVE-2018-14056 in the following references: [link1], [link2], [link3].