CVE-2015-8702
published 2016-04-12CVE-2015-8702: The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in…
PriorityP336high8.6CVSS 3.0
AVNACLPRNUINSCCNINAH
EPSS
2.28%
81.4th percentile
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | inspircd | < inspircd 2.0.20-1 (bookworm) | inspircd 2.0.20-1 (bookworm) |
| inspircd | inspircd | <= 2.0.18 | — |
| inspircd | inspircd | >= 0 < 2.0.20-1 | 2.0.20-1 |
| inspircd | inspircd | >= 0 < 2.0.20-1 | 2.0.20-1 |
| inspircd | inspircd | >= 0 < 2.0.20-1 | 2.0.20-1 |
| inspircd | inspircd | >= 0 < 2.0.20-1 | 2.0.20-1 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv8.6HIGH
vendor_debian8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-45pp-chxf-3x9r: The DNS::GetResult function in dns
ghsa_unreviewed·2022-05-13
CVE-2015-8702 [HIGH] CWE-20 GHSA-45pp-chxf-3x9r: The DNS::GetResult function in dns
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.
OSV
CVE-2015-8702: The DNS::GetResult function in dns
osv·2016-04-12·CVSS 8.6
CVE-2015-8702 [HIGH] CVE-2015-8702: The DNS::GetResult function in dns
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.
Debian
CVE-2015-8702: inspircd - The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote D...
vendor_debian·2015·CVSS 8.6
CVE-2015-8702 [HIGH] CVE-2015-8702: inspircd - The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote D...
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.
Scope: local
bookworm: resolved (fixed in 2.0.20-1)
bullseye: resolved (fixed in 2.0.20-1)
forky: resolved (fixed in 2.0.20-1)
sid: resolved (fixed in 2.0.20-1)
trixie: resolved (fixed in 2.0.20-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2016/dsa-3527http://www.inspircd.org/2015/04/16/v2019-released.htmlhttps://github.com/inspircd/inspircd/commit/6058483d9fbc1b904d5ae7cfea47bfcde5c5b559https://github.com/inspircd/inspircd/issues/1033https://security.gentoo.org/glsa/201512-13http://www.debian.org/security/2016/dsa-3527http://www.inspircd.org/2015/04/16/v2019-released.htmlhttps://github.com/inspircd/inspircd/commit/6058483d9fbc1b904d5ae7cfea47bfcde5c5b559https://github.com/inspircd/inspircd/issues/1033https://security.gentoo.org/glsa/201512-13
2016-04-12
Published