CVE-2020-14148: High severity ngircd vulnerability
Published Jun 15, 2020
·Updated
The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRCNJOIN() function.
Affected Software
5 affected components
Barton Ngircd<=25.0
Barton Ngircd=26.0-rc1
Debian Debian Linux=8.0
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Remediation
Patch Available
Event History
Jun 15, 2020
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-14148?
CVE-2020-14148 is classified as a medium severity vulnerability due to its potential for causing out-of-bounds access.
2
How do I fix CVE-2020-14148?
To fix CVE-2020-14148, update ngIRCd to version 26~rc2 or later.
3
What causes the vulnerability CVE-2020-14148?
CVE-2020-14148 is caused by an out-of-bounds access in the Server-Server protocol implementation of ngIRCd.
4
Which versions of ngIRCd are affected by CVE-2020-14148?
Versions of ngIRCd prior to 26~rc2, including all versions up to and including 25.0 and 26.0-rc1, are affected by CVE-2020-14148.
5
What is the impact of exploiting CVE-2020-14148?
Exploiting CVE-2020-14148 may lead to unpredictable behavior or service disruptions in affected systems.