CVE-2016-7144: High severity UnrealIRCd UnrealIRCd vulnerability
Published Jan 18, 2017
·Updated
The mauthenticate function in modules/msasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
Affected Software
8 affected components
UnrealIRCd UnrealIRCd<=3.2.10.5
UnrealIRCd UnrealIRCd=4.0.0
UnrealIRCd UnrealIRCd=4.0.1
UnrealIRCd UnrealIRCd=4.0.2
UnrealIRCd UnrealIRCd=4.0.3
UnrealIRCd UnrealIRCd=4.0.3.1
UnrealIRCd UnrealIRCd=4.0.4
UnrealIRCd UnrealIRCd=4.0.5
Remediation
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7144?
CVE-2016-7144 has a high severity rating of 8.1 according to the CVSS 3.0 scoring system.
2
How do I fix CVE-2016-7144?
To mitigate CVE-2016-7144, apply the available patches for UnrealIRCd versions 3.2.10.7 and later, or version 4.0.6 and later.
3
What kind of vulnerability is CVE-2016-7144?
CVE-2016-7144 is a remote authentication vulnerability that allows attackers to spoof certificate fingerprints.
4
Who is affected by CVE-2016-7144?
Users of UnrealIRCd versions before 3.2.10.7 and 4.0.6 are at risk due to CVE-2016-7144.
5
When was CVE-2016-7144 published?
CVE-2016-7144 was published on January 18, 2017.