Candidate: CVE-2016-7143 PublicDate: 2016-09-21 14:25:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7143 Description: The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter. Ubuntu-Description: It was discovered that Charybdis incorrectly handled AUTHENTICATE parameters. An attacker could possibly use this issue to log in as another user. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=836714 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_charybdis: upstream: https://github.com/charybdis-ircd/charybdis/commit/818a3fda944b26d4814132cee14cfda4ea4aa824 upstream_charybdis: released (3.5.3-1) precise_charybdis: ignored (reached end-of-life) precise/esm_charybdis: DNE (precise was needs-triage) trusty_charybdis: ignored (reached end-of-life) trusty/esm_charybdis: DNE (trusty was needed) vivid/stable-phone-overlay_charybdis: DNE vivid/ubuntu-core_charybdis: DNE xenial_charybdis: ignored (end of standard support, was needed) yakkety_charybdis: ignored (reached end-of-life) zesty_charybdis: ignored (reached end-of-life) artful_charybdis: ignored (reached end-of-life) bionic_charybdis: not-affected (3.5.3-1) cosmic_charybdis: not-affected (3.5.3-1) disco_charybdis: not-affected (3.5.3-1) eoan_charybdis: not-affected (3.5.3-1) focal_charybdis: not-affected (3.5.3-1) groovy_charybdis: not-affected (3.5.3-1) hirsute_charybdis: not-affected (3.5.3-1) impish_charybdis: DNE jammy_charybdis: DNE devel_charybdis: DNE