6.8
CVSSv2

CVE-2019-20917

Published: 11/09/2020 Updated: 27/01/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

An issue exists in InspIRCd 2 prior to 2.0.28 and 3 prior to 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

inspircd inspircd

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Two security issues were discovered in the pgsql and mysql modules of the InspIRCd IRC daemon, which could result in denial of service For the stable distribution (buster), these problems have been fixed in version 2027-1+deb10u1 We recommend that you upgrade your inspircd packages For the detailed security status of inspircd please refer to i ...