CVE Vulnerabilities

CVE-2019-20917

NULL Pointer Dereference

Published: Sep 11, 2020 | Modified: Jan 27, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Inspircd Inspircd 2.0 (including) 2.0.28 (excluding)
Inspircd Inspircd 3.0 (including) 3.3.0 (excluding)
Inspircd Ubuntu bionic *
Inspircd Ubuntu trusty *
Inspircd Ubuntu upstream *
Inspircd Ubuntu xenial *

Potential Mitigations

References