Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-10209

net-irc/inspircd - vulnerabilities

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Fixed
    • Icon: Medium (Ebuild) Medium (Ebuild)
    • None
    • None
    • Vulnerabilities can remotely crash inspircd.

      originally reported here: https://github.com/funtoo/net-kit/issues/7

      {
        "id": "CVE-2020-25269",
        "is_known_exploited_vuln": null,
        "description": "An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.",
        "urls": [
          "https://nvd.nist.gov/vuln/detail/CVE-2020-25269",
          "https://github.com/inspircd/inspircd/compare/v2.0.28...07d7dea",
          "https://docs.inspircd.org/security/2020-01/",
          "https://github.com/inspircd/inspircd/compare/426d1c8...b3f1db9",
          "https://www.debian.org/security/2020/dsa-4764",
          "https://lists.debian.org/debian-lts-announce/2020/09/msg00015.html"
        ]
      }
      {
        "id": "CVE-2019-20917",
        "is_known_exploited_vuln": null,
        "description": "An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.",
        "urls": [
          "https://nvd.nist.gov/vuln/detail/CVE-2019-20917",
          "https://docs.inspircd.org/security/2019-02/",
          "https://github.com/inspircd/inspircd/commit/2cc35d8625b7ea5cbd1d1ebb116aff86c5280162",
          "https://github.com/inspircd/inspircd/commit/8745660fcdac7c1b80c94cfc0ff60928cd4dd4b7",
          "https://www.debian.org/security/2020/dsa-4764",
          "https://lists.debian.org/debian-lts-announce/2020/09/msg00015.html"
        ]
      }
      

            mrl5 mrl5
            mrl5 mrl5
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: