CVE-2016-7142: Medium severity inspircd vulnerability
The msasl module in InspIRCd before 2.0.23, when used with a service that supports SASLEXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7142?
CVE-2016-7142 is considered a high severity vulnerability as it allows remote attackers to spoof certificate fingerprints and log in as another user.
How do I fix CVE-2016-7142?
To mitigate CVE-2016-7142, upgrade to InspIRCd version 2.0.23 or later and ensure SASL_EXTERNAL authentication is properly configured.
What software is affected by CVE-2016-7142?
CVE-2016-7142 affects InspIRCd versions before 2.0.23 and Debian GNU/Linux 8.0.
Can CVE-2016-7142 be exploited remotely?
Yes, CVE-2016-7142 can be exploited remotely via crafted SASL messages.
What types of attacks can be conducted using CVE-2016-7142?
CVE-2016-7142 allows attackers to impersonate other users by spoofing certificate fingerprints through SASL authentication.