Vulnerability Description
The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nefarious2 Project | Nefarious2 | 2.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/09/05/9Mailing ListPatchThird Party Advisory
- https://github.com/evilnet/nefarious2/commit/f50a84bad996d438e7b31b9e74c32a41e43Issue TrackingPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/09/05/9Mailing ListPatchThird Party Advisory
- https://github.com/evilnet/nefarious2/commit/f50a84bad996d438e7b31b9e74c32a41e43Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2016-7145?
CVE-2016-7145 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE paramete...
How severe is CVE-2016-7145?
CVE-2016-7145 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-7145?
Check the references section above for vendor advisories and patch information. Affected products include: Nefarious2 Project Nefarious2.