The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Inspircd | Inspircd | * | 2.0.22 (including) |
Inspircd | Ubuntu | artful | * |
Inspircd | Ubuntu | esm-apps/xenial | * |
Inspircd | Ubuntu | precise | * |
Inspircd | Ubuntu | trusty | * |
Inspircd | Ubuntu | upstream | * |
Inspircd | Ubuntu | xenial | * |
Inspircd | Ubuntu | yakkety | * |
Inspircd | Ubuntu | zesty | * |