CVE-2019-20917
published 2020-09-11CVE-2019-20917: An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.79%
85.0th percentile
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | inspircd | < inspircd 3.3.0-1 (bookworm) | inspircd 3.3.0-1 (bookworm) |
| inspircd | inspircd | >= 0 < 3.3.0-1 | 3.3.0-1 |
| inspircd | inspircd | >= 0 < 3.3.0-1 | 3.3.0-1 |
| inspircd | inspircd | >= 0 < 3.3.0-1 | 3.3.0-1 |
| inspircd | inspircd | >= 0 < 3.3.0-1 | 3.3.0-1 |
| inspircd | inspircd | >= 0 < 2.0.20-5ubuntu0.1~esm1 | 2.0.20-5ubuntu0.1~esm1 |
| inspircd | inspircd | >= 0 < 2.0.24-1ubuntu1+esm1 | 2.0.24-1ubuntu1+esm1 |
| inspircd | inspircd | >= 0 < 3.4.0-2ubuntu1+esm1 | 3.4.0-2ubuntu1+esm1 |
| inspircd | inspircd | >= 2.0 < 2.0.28 | 2.0.28 |
| inspircd | inspircd | >= 3.0 < 3.3.0 | 3.3.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
inspircd vulnerabilities
osv·2025-04-02·CVSS 5.9
CVE-2016-7142 [MEDIUM] inspircd vulnerabilities
inspircd vulnerabilities
It was discovered that InspIRCd did not correctly handle certificate
fingerprints, which could lead to spoofing. A remote attacker could
possibly use this issue to bypass authentication. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-7142)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a NULL pointer dereference. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-20917)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a use-after-free. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2020-25269)
GHSA
GHSA-8h73-696h-wwm7: An issue was discovered in InspIRCd 2 before 2
ghsa_unreviewed·2022-05-24
CVE-2019-20917 [MEDIUM] CWE-476 GHSA-8h73-696h-wwm7: An issue was discovered in InspIRCd 2 before 2
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
OSV
CVE-2019-20917: An issue was discovered in InspIRCd 2 before 2
osv·2020-09-11·CVSS 6.5
CVE-2019-20917 [MEDIUM] CVE-2019-20917: An issue was discovered in InspIRCd 2 before 2
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
Ubuntu
InspIRCd vulnerabilities
vendor_ubuntu·2025-04-02·CVSS 5.9
CVE-2020-25269 [MEDIUM] InspIRCd vulnerabilities
Title: InspIRCd vulnerabilities
Summary: Several security issues were fixed in InspIRCd.
It was discovered that InspIRCd did not correctly handle certificate
fingerprints, which could lead to spoofing. A remote attacker could
possibly use this issue to bypass authentication. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-7142)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a NULL pointer dereference. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-20917)
It was discovered that InspIRCd did not correctly handle certain memory
operations, which could lead to a use-after-free. A remote attacker could
possibly use this issue
Debian
CVE-2019-20917: inspircd - An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysq...
vendor_debian·2019·CVSS 6.5
CVE-2019-20917 [MEDIUM] CVE-2019-20917: inspircd - An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysq...
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
Scope: local
bookworm: resolved (fixed in 3.3.0-1)
bullseye: resolved (fixed in 3.3.0-1)
forky: resolved (fixed in 3.3.0-1)
sid: resolved (fixed in 3.3.0-1)
trixie: resolved (fixed in 3.3.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://docs.inspircd.org/security/2019-02/https://github.com/inspircd/inspircd/commit/2cc35d8625b7ea5cbd1d1ebb116aff86c5280162https://github.com/inspircd/inspircd/commit/8745660fcdac7c1b80c94cfc0ff60928cd4dd4b7https://lists.debian.org/debian-lts-announce/2020/09/msg00015.htmlhttps://www.debian.org/security/2020/dsa-4764https://docs.inspircd.org/security/2019-02/https://github.com/inspircd/inspircd/commit/2cc35d8625b7ea5cbd1d1ebb116aff86c5280162https://github.com/inspircd/inspircd/commit/8745660fcdac7c1b80c94cfc0ff60928cd4dd4b7https://lists.debian.org/debian-lts-announce/2020/09/msg00015.htmlhttps://www.debian.org/security/2020/dsa-4764
2020-09-11
Published