DescriptionAn issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2375-1, DSA-4764-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
inspircd (PTS)buster, buster (security)2.0.27-1+deb10u1fixed
sid, trixie, bookworm3.15.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs

Notes (v2) (v3)

Search for package or bug name: Reporting problems