CVE Vulnerabilities

CVE-2019-20917

NULL Pointer Dereference

Published: Sep 11, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Inspircd Inspircd 2.0 (including) 2.0.28 (excluding)
Inspircd Inspircd 3.0 (including) 3.3.0 (excluding)
Inspircd Ubuntu bionic *
Inspircd Ubuntu esm-apps/bionic *
Inspircd Ubuntu esm-apps/xenial *
Inspircd Ubuntu trusty *
Inspircd Ubuntu upstream *
Inspircd Ubuntu xenial *

Potential Mitigations

References