VulnerabilityModified
CVE-2021-33586
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.
MEDIUM 4.3EPSS 0.89%
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- inspircd/inspircd
- Source
- cve@mitre.org
References
- https://docs.inspircd.org/security/2021-01/Patch, Vendor Advisory
- https://github.com/inspircd/inspircd/commit/4350a11c663b0d75f8119743bffb7736d87abd4dPatch, Third Party Advisory
- https://security.gentoo.org/glsa/202107-22Third Party Advisory
- https://docs.inspircd.org/security/2021-01/Patch, Vendor Advisory
- https://github.com/inspircd/inspircd/commit/4350a11c663b0d75f8119743bffb7736d87abd4dPatch, Third Party Advisory
- https://security.gentoo.org/glsa/202107-22Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.