Candidate: CVE-2015-8702 PublicDate: 2016-04-12 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8702 https://github.com/inspircd/inspircd/commit/6058483d9fbc1b904d5ae7cfea47bfcde5c5b559 http://www.inspircd.org/2015/04/16/v2019-released.html Description: The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H [8.6 HIGH] Patches_inspircd: upstream_inspircd: released (2.0.20-1) precise_inspircd: released (1.1.22+dfsg-4+squeeze3ubuntu0.1) trusty_inspircd: released (2.0.5-1+deb7u2build0.14.04.1) trusty/esm_inspircd: DNE (trusty was released [2.0.5-1+deb7u2build0.14.04.1]) vivid_inspircd: ignored (reached end-of-life) vivid/stable-phone-overlay_inspircd: DNE vivid/ubuntu-core_inspircd: DNE wily_inspircd: not-affected (2.0.20-3) xenial_inspircd: not-affected devel_inspircd: not-affected