Bug#903788: znc: path traversal flaw

2018-07-14 Thread Salvatore Bonaccorso
Control: retitle -1 znc: CVE-2018-14056: path traversal flaw On Sat, Jul 14, 2018 at 10:02:58PM +0200, Salvatore Bonaccorso wrote: > Source: znc > Version: 0.045-1 > Severity: grave > Tags: patch security upstream > Justification: user security hole > > Hi > > See https://github.com/znc/znc/comm

Bug#903788: znc: path traversal flaw

2018-07-14 Thread Salvatore Bonaccorso
Source: znc Version: 0.045-1 Severity: grave Tags: patch security upstream Justification: user security hole Hi See https://github.com/znc/znc/commit/a4a5aeeb17d32937d8c7d743dae9a4cc755ce773 allowing path traversal and can lead to expose some files which shouldn't be, or potentially lead to a cra