First published: Fri Sep 11 2020(Updated: )
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/inspircd | 2.0.27-1+deb10u1 3.8.1-2 3.15.0-1 | |
Inspircd Inspircd | >=2.0<2.0.28 | |
Inspircd Inspircd | >=3.0<3.3.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.