CVE-2021-33586: Medium severity inspircd vulnerability
Published May 27, 2021
·Updated
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.
Affected Software
1 affected component
inspircd inspircd>=3.8.0<3.10.0
Remediation
Patch Available
Event History
May 27, 2021
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-33586?
CVE-2021-33586 is considered a moderate severity vulnerability due to its potential for disrupting service via memory access issues.
2
Who is affected by CVE-2021-33586?
CVE-2021-33586 affects all users of InspIRCd from versions 3.8.0 to 3.9.x before 3.10.0.
3
How do I fix CVE-2021-33586?
To fix CVE-2021-33586, you should upgrade to InspIRCd version 3.10.0 or later.
4
What kind of issue does CVE-2021-33586 represent?
CVE-2021-33586 represents an issue that allows any user to access recently deallocated memory through a malformed PONG message.
5
Is there a workaround for CVE-2021-33586?
There is no documented workaround for CVE-2021-33586, and upgrading is the advised solution.