CVE-2022-24976: Critical severity atheme vulnerability
Published Feb 13, 2022
·Updated
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
Affected Software
1 affected component
Atheme Atheme>=7.2.0<7.2.12
Remediation
Patch Available
Event History
Feb 13, 2022
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-24976?
The severity of CVE-2022-24976 is classified as high due to the potential for authentication bypass.
2
How do I fix CVE-2022-24976?
To fix CVE-2022-24976, upgrade Atheme IRC Services to version 7.2.12 or later.
3
Which versions of Atheme IRC Services are affected by CVE-2022-24976?
Versions of Atheme IRC Services prior to 7.2.12 are affected by CVE-2022-24976.
4
What is the impact of CVE-2022-24976?
The impact of CVE-2022-24976 is an authentication bypass that could allow unauthorized access to the system.
5
Does CVE-2022-24976 affect other software besides Atheme IRC Services?
CVE-2022-24976 specifically affects Atheme IRC Services when used in conjunction with InspIRCd.