-
-
Notifications
You must be signed in to change notification settings - Fork 24
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add the change log and security advisory for v4.0.1.
- Loading branch information
Showing
3 changed files
with
59 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,39 @@ | ||
--- | ||
title: Security Advisory 2024-01 | ||
--- | ||
|
||
## InspIRCd Security Advisory 2024-01 | ||
|
||
### Summary | ||
|
||
The spanningtree module before v4.0.1 contains a null pointer dereference. When the chanhistory module is also loaded this vulnerability can be used to remotely crash a InspIRCd server by any user able to connect to a server and set channel modes. | ||
|
||
Thanks to [@RobCubed](https://github.com/RobCubed) for reporting this issue. | ||
|
||
### Affected Versions | ||
|
||
This vulnerability is present in the following releases: | ||
|
||
* v4.0.0a26 | ||
* v4.0.0rc1 | ||
* v4.0.0rc2 | ||
* v4.0.0rc3 | ||
* v4.0.0 | ||
|
||
### Recommended Action | ||
|
||
This vulnerability is fixed in version 4.0.1. It is strongly recommended that all affected users upgrade. | ||
|
||
If upgrading is not possible then the spanningtree module should be unloaded. If this is also not possible then the chanhistory module should be unloaded. | ||
|
||
### History | ||
|
||
* 2024-03-08 — The vulnerability was introduced. | ||
* 2024-07-02 — A crash vulnerability was reported to the InspIRCd team. | ||
* 2024-07-02 — The cause of the crash was identified by the InspIRCd team and a fix was prepared. | ||
* 2024-07-03 — InspIRCd v4.0.1 was released with a fix for the crash vulnerability. | ||
|
||
### References | ||
|
||
* [InspIRCd commit ef572e3](https://github.com/inspircd/inspircd/commit/ef572e3c1feee05f7aafb266c29e566f56ea268a). | ||
* [InspIRCd commit b1f5817](https://github.com/inspircd/inspircd/commit/b1f581787dd29a515a4bc09c2d9a2df5b1c7938e). |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters