CVE-2016-7144
18.01.2017, 17:59
The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.Enginsight
Vendor | Product | Version |
---|---|---|
unrealircd | unrealircd | 𝑥 ≤ 3.2.10.5 |
unrealircd | unrealircd | 4.0.0 |
unrealircd | unrealircd | 4.0.1 |
unrealircd | unrealircd | 4.0.2 |
unrealircd | unrealircd | 4.0.3 |
unrealircd | unrealircd | 4.0.3.1 |
unrealircd | unrealircd | 4.0.4 |
unrealircd | unrealircd | 4.0.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References