NULL pointer dereference in InspIRCd - CVE-2019-20917

 

NULL pointer dereference in InspIRCd - CVE-2019-20917

Published: September 11, 2020 / Updated: September 20, 2020


Vulnerability identifier: #VU46821
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20917
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in mysql module, when built against mariadb-connector-c 3.0.5 or newer.  A remote user can send specially crafted request to the InspIRCd daemon, trigger a NULL pointer dereference error and crash the server.

Successful exploitation of the vulnerability requires that sqlauth or sqloper modules are used.


Affected software

InspIRCd
inspircd (Debian package)

How to mitigate CVE-2019-20917

Install update from vendor's website.

InspIRCd - addressed in versions 2.0.28, 3.3.0
inspircd (Debian package) - update to 2.0.27-1+deb10u1

External References

Related Security Bulletins