VulnerabilityModified
CVE-2020-25269
The pgsql module contains a use after free vulnerability.
MEDIUM 6.5EPSS 2.69%
Does this matter?
Lower severity and a low EPSS score (2.69%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.69% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- inspircd/inspircd · debian/debian linux
- Source
- cve@mitre.org
References
- https://docs.inspircd.org/security/2020-01/Vendor Advisory
- https://github.com/inspircd/inspircd/compare/426d1c8...b3f1db9Patch, Third Party Advisory
- https://github.com/inspircd/inspircd/compare/v2.0.28...07d7deaPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00015.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4764Third Party Advisory
- https://docs.inspircd.org/security/2020-01/Vendor Advisory
- https://github.com/inspircd/inspircd/compare/426d1c8...b3f1db9Patch, Third Party Advisory
- https://github.com/inspircd/inspircd/compare/v2.0.28...07d7deaPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00015.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4764Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.