Vulnerability Description
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inspircd | Inspircd | >= 2.0, < 2.0.28 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://docs.inspircd.org/security/2019-02/Vendor Advisory
- https://github.com/inspircd/inspircd/commit/2cc35d8625b7ea5cbd1d1ebb116aff86c528PatchThird Party Advisory
- https://github.com/inspircd/inspircd/commit/8745660fcdac7c1b80c94cfc0ff60928cd4dPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00015.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2020/dsa-4764Third Party Advisory
- https://docs.inspircd.org/security/2019-02/Vendor Advisory
- https://github.com/inspircd/inspircd/commit/2cc35d8625b7ea5cbd1d1ebb116aff86c528PatchThird Party Advisory
- https://github.com/inspircd/inspircd/commit/8745660fcdac7c1b80c94cfc0ff60928cd4dPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00015.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2020/dsa-4764Third Party Advisory
FAQ
What is CVE-2019-20917?
CVE-2019-20917 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with t...
How severe is CVE-2019-20917?
CVE-2019-20917 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20917?
Check the references section above for vendor advisories and patch information. Affected products include: Inspircd Inspircd, Debian Debian Linux.