CVE-2019-20917: Null Pointer Dereference
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20917?
CVE-2019-20917 has a high severity due to the potential for remote crashing of the InspIRCd server.
How do I fix CVE-2019-20917?
To fix CVE-2019-20917, upgrade to InspIRCd version 2.0.28 or newer for version 2.x, or version 3.3.0 or newer for version 3.x.
Which versions of InspIRCd are affected by CVE-2019-20917?
InspIRCd versions prior to 2.0.28 and 3.0 to 3.2.9 are affected by CVE-2019-20917.
What components need to be considered with CVE-2019-20917?
CVE-2019-20917 is relevant when the mysql module is built against mariadb-connector-c version 3.0.5 or newer.
Can CVE-2019-20917 be exploited remotely?
Yes, CVE-2019-20917 can be exploited remotely, leading to the potential crashing of the InspIRCd server.