Package        : znc
Version        : 1.4-2+deb8u1
CVE IDs        : CVE-2018-14055 CVE-2018-14056 
Debian Bugs    : #903787 #903788

It was discovered that there were two issues in znc, a modular IRC
bouncer:

  * There was insufficient validation of lines coming from the network
    allowing a non-admin user to escalate his privilege and inject rogue
    values into znc.conf. (CVE-2018-14055)

  * A path traversal vulnerability (via "../" being embedded in a web skin
    name) to access files outside of the allowed directory.
    (CVE-2018-14056)

For Debian 8 "Jessie", these issues have been fixed in znc version
1.4-2+deb8u1.

We recommend that you upgrade your znc packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1427-1: znc security update

July 15, 2018
It was discovered that there were two issues in znc, a modular IRC bouncer: * There was insufficient validation of lines coming from the network

Summary

* A path traversal vulnerability (via "../" being embedded in a web skin
name) to access files outside of the allowed directory.
(CVE-2018-14056)

For Debian 8 "Jessie", these issues have been fixed in znc version
1.4-2+deb8u1.

We recommend that you upgrade your znc packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : znc
Version : 1.4-2+deb8u1

Related News