CVE-2016-7142
published 2016-09-26CVE-2016-7142: The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.08%
61.8th percentile
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | inspircd | < inspircd 2.0.23-1 (bookworm) | inspircd 2.0.23-1 (bookworm) |
| inspircd | inspircd | <= 2.0.22 | — |
| inspircd | inspircd | >= 0 < 2.0.23-1 | 2.0.23-1 |
| inspircd | inspircd | >= 0 < 2.0.23-1 | 2.0.23-1 |
| inspircd | inspircd | >= 0 < 2.0.23-1 | 2.0.23-1 |
| inspircd | inspircd | >= 0 < 2.0.23-1 | 2.0.23-1 |
| inspircd | inspircd | >= 0 < 2.0.20-5ubuntu0.1~esm1 | 2.0.20-5ubuntu0.1~esm1 |
| inspircd | inspircd | >= 0 < 2.0.24-1ubuntu1+esm1 | 2.0.24-1ubuntu1+esm1 |
| inspircd | inspircd | >= 0 < 3.4.0-2ubuntu1+esm1 | 3.4.0-2ubuntu1+esm1 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
inspircd vulnerabilities
osv·2025-04-02·CVSS 5.9
CVE-2016-7142 [MEDIUM] inspircd vulnerabilities
inspircd vulnerabilities
It was discovered that InspIRCd did not correctly handle certificate
fingerprints, which could lead to spoofing. A remote attacker could
possibly use this issue to bypass authentication. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-7142)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a NULL pointer dereference. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-20917)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a use-after-free. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2020-25269)
GHSA
GHSA-2vvc-952f-f8xg: The m_sasl module in InspIRCd before 2
ghsa_unreviewed·2022-05-13
CVE-2016-7142 [MEDIUM] GHSA-2vvc-952f-f8xg: The m_sasl module in InspIRCd before 2
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
OSV
CVE-2016-7142: The m_sasl module in InspIRCd before 2
osv·2016-09-26·CVSS 5.9
CVE-2016-7142 [MEDIUM] CVE-2016-7142: The m_sasl module in InspIRCd before 2
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
Ubuntu
InspIRCd vulnerabilities
vendor_ubuntu·2025-04-02·CVSS 5.9
CVE-2020-25269 [MEDIUM] InspIRCd vulnerabilities
Title: InspIRCd vulnerabilities
Summary: Several security issues were fixed in InspIRCd.
It was discovered that InspIRCd did not correctly handle certificate
fingerprints, which could lead to spoofing. A remote attacker could
possibly use this issue to bypass authentication. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-7142)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a NULL pointer dereference. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-20917)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a use-after-free. A remote attacker could
possibly use this issue
Debian
CVE-2016-7142: inspircd - The m_sasl module in InspIRCd before 2.0.23, when used with a service that suppo...
vendor_debian·2016·CVSS 5.9
CVE-2016-7142 [MEDIUM] CVE-2016-7142: inspircd - The m_sasl module in InspIRCd before 2.0.23, when used with a service that suppo...
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
Scope: local
bookworm: resolved (fixed in 2.0.23-1)
bullseye: resolved (fixed in 2.0.23-1)
forky: resolved (fixed in 2.0.23-1)
sid: resolved (fixed in 2.0.23-1)
trixie: resolved (fixed in 2.0.23-1)
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2016/dsa-3662http://www.inspircd.org/2016/09/03/v2023-released.htmlhttp://www.openwall.com/lists/oss-security/2016/09/04/3http://www.openwall.com/lists/oss-security/2016/09/05/8https://github.com/inspircd/inspircd/commit/74fafb7f11b06747f69f182ad5e3769b665eea7ahttp://www.debian.org/security/2016/dsa-3662http://www.inspircd.org/2016/09/03/v2023-released.htmlhttp://www.openwall.com/lists/oss-security/2016/09/04/3http://www.openwall.com/lists/oss-security/2016/09/05/8https://github.com/inspircd/inspircd/commit/74fafb7f11b06747f69f182ad5e3769b665eea7a
2016-09-26
Published