CVE-2016-7144

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
18/01/2017
Last modified:
20/04/2025

Description

The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unrealircd:unrealircd:*:*:*:*:*:*:*:* 3.2.10.5 (including)
cpe:2.3:a:unrealircd:unrealircd:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:unrealircd:unrealircd:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:unrealircd:unrealircd:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:unrealircd:unrealircd:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:unrealircd:unrealircd:4.0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:unrealircd:unrealircd:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:unrealircd:unrealircd:4.0.5:*:*:*:*:*:*:*