ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade znc | Jul 20, 2018 | Jul 15, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 15, 2018 |
| Debian | — | Upgrade znc | Jul 20, 2018 | Jul 14, 2018 |
| Freebsd | — | Upgrade znc | Jul 19, 2018 | Jul 18, 2018 |
| Gentoo Linux | — | Upgrade net-irc/znc. | Jul 30, 2018 | Jul 14, 2018 |
| Suse | — | Upgrade znc-tclUpgrade znc-python3Upgrade znc-perlUpgrade znc-langUpgrade zncUpgrade znc-devel | Aug 8, 2018 | Jul 14, 2018 |
| Ubuntu | — | Upgrade znc | Nov 19, 2024 | Jul 15, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub