The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.
(CVE-2020-14148)
- https://bugs.mageia.org/show_bug.cgi?id=26853
- https://lists.debian.org/debian-lts-announce/2020/06/msg00023.html
- https://www.cve.org/CVERecord?id=CVE-2020-14148
- 7/core/ngircd-25-1.1.mga7
Get the latest Linux and open source security news straight to your inbox.