ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.
| Software | From | Fixed in |
|---|---|---|
| znc / znc | - | 1.7.0.x |
| debian / debian_linux | 9.0 | 9.0.x |