CVE-2020-25269
Summary
| CVE | CVE-2020-25269 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-11 05:15:00 UTC |
| Updated | 2023-01-24 02:09:00 UTC |
| Description | An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server. |
Risk And Classification
Problem Types: CWE-416
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Inspircd | Inspircd | All | All | All | All |
| Application | Inspircd | Inspircd | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 2375-1] inspircd security update | MLIST | lists.debian.org | |
| Security Advisory 2020-01 - InspIRCd Documentation | MISC | docs.inspircd.org | Vendor Advisory |
| Debian -- Security Information -- DSA-4764-1 inspircd | DEBIAN | www.debian.org | |
| Comparing v2.0.28...07d7dea · inspircd/inspircd · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Comparing 426d1c8...b3f1db9 · inspircd/inspircd · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.