CVE-2015-8702: Input Validation
Published Apr 12, 2016
·Updated
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.
Affected Software
3 affected components
Debian Debian Linux=7.0
Debian Debian Linux=8.0
inspircd inspircd<=2.0.18
Event History
Apr 12, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8702?
CVE-2015-8702 is classified as a denial of service vulnerability that can lead to a netsplit in InspIRCd.
2
How do I fix CVE-2015-8702?
To mitigate CVE-2015-8702, users should upgrade to InspIRCd version 2.0.19 or later.
3
Which software versions are affected by CVE-2015-8702?
InspIRCd versions prior to 2.0.19 and Debian GNU/Linux versions 7.0 and 8.0 are affected by CVE-2015-8702.
4
What kind of attack does CVE-2015-8702 facilitate?
CVE-2015-8702 allows remote DNS servers to cause a denial of service through invalid characters in PTR responses.
5
When was CVE-2015-8702 discovered?
CVE-2015-8702 was discovered and disclosed in April 2015.