CVE-2019-20917

NameCVE-2019-20917
DescriptionAn issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2375-1, DSA-4764-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
inspircd (PTS)stretch2.0.23-2vulnerable
stretch (security)2.0.23-2+deb9u1fixed
buster, buster (security)2.0.27-1+deb10u1fixed
bullseye, sid3.4.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
inspircdsourcestretch2.0.23-2+deb9u1DLA-2375-1
inspircdsourcebuster2.0.27-1+deb10u1DSA-4764-1
inspircdsource(unstable)3.3.0-1

Notes

https://docs.inspircd.org/security/2019-02/
https://github.com/inspircd/inspircd/commit/2cc35d8625b7ea5cbd1d1ebb116aff86c5280162 (v2)
https://github.com/inspircd/inspircd/commit/8745660fcdac7c1b80c94cfc0ff60928cd4dd4b7 (v3)

Search for package or bug name: Reporting problems