cbcvebase.
CVE-2019-20917
published 2020-09-11

CVE-2019-20917: An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against…

PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.79%
85.0th percentile
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianinspircd< inspircd 3.3.0-1 (bookworm)inspircd 3.3.0-1 (bookworm)
inspircdinspircd>= 0 < 3.3.0-13.3.0-1
inspircdinspircd>= 0 < 3.3.0-13.3.0-1
inspircdinspircd>= 0 < 3.3.0-13.3.0-1
inspircdinspircd>= 0 < 3.3.0-13.3.0-1
inspircdinspircd>= 0 < 2.0.20-5ubuntu0.1~esm12.0.20-5ubuntu0.1~esm1
inspircdinspircd>= 0 < 2.0.24-1ubuntu1+esm12.0.24-1ubuntu1+esm1
inspircdinspircd>= 0 < 3.4.0-2ubuntu1+esm13.4.0-2ubuntu1+esm1
inspircdinspircd>= 2.0 < 2.0.282.0.28
inspircdinspircd>= 3.0 < 3.3.03.3.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.