First published: Fri Sep 11 2020(Updated: )
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/inspircd | 2.0.27-1+deb10u1 3.8.1-2 3.15.0-1 | |
InspIRCd | >=2.0<2.0.28 | |
InspIRCd | >=3.0<3.3.0 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20917 has a high severity due to the potential for remote crashing of the InspIRCd server.
To fix CVE-2019-20917, upgrade to InspIRCd version 2.0.28 or newer for version 2.x, or version 3.3.0 or newer for version 3.x.
InspIRCd versions prior to 2.0.28 and 3.0 to 3.2.9 are affected by CVE-2019-20917.
CVE-2019-20917 is relevant when the mysql module is built against mariadb-connector-c version 3.0.5 or newer.
Yes, CVE-2019-20917 can be exploited remotely, leading to the potential crashing of the InspIRCd server.