First published: Fri Sep 11 2020(Updated: )
An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/inspircd | 2.0.27-1+deb10u1 3.8.1-2 3.15.0-1 | |
InspIRCd | >=2.0<2.0.29 | |
InspIRCd | >=3.0<3.6.0 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25269 is classified as a high severity vulnerability due to its potential to cause remote server crashes.
To fix CVE-2020-25269, upgrade to InspIRCd version 2.0.29 or later, or version 3.6.0 or later.
InspIRCd versions prior to 2.0.29 and versions prior to 3.6.0 are affected by CVE-2020-25269.
The primary risk associated with CVE-2020-25269 is the ability for remote users to crash the InspIRCd server.
The vulnerabilities in CVE-2020-25269 can be exploited when the pgsql module is used in conjunction with the sqlauth or sqloper modules.