CVE-2016-7143
21.09.2016, 14:25
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.Enginsight
Vendor | Product | Version |
---|---|---|
debian | debian_linux | 8.0 |
charybdis_project | charybdis | 𝑥 ≤ 3.5.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References