Vulnerability Name: | CVE-2015-8702 (CCN-110085) | ||||||||||||||||||||||||
Assigned: | 2015-12-29 | ||||||||||||||||||||||||
Published: | 2015-12-29 | ||||||||||||||||||||||||
Updated: | 2020-09-14 | ||||||||||||||||||||||||
Summary: | The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname. | ||||||||||||||||||||||||
CVSS v3 Severity: | 8.6 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H) 7.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8702 Source: CCN Type: oss-sec Mailing List, Tue, 29 Dec 2015 11:31:04 -0500 (EST) Re: Inspircd <2.0.19 DoS Source: DEBIAN Type: Vendor Advisory DSA-3527 Source: CONFIRM Type: Vendor Advisory http://www.inspircd.org/2015/04/16/v2019-released.html Source: XF Type: UNKNOWN inspircd-cve20158702-dos(110085) Source: CCN Type: inspircd GIT Repository Reject replies to DNS PTR requests that contain invalid characters Source: CONFIRM Type: Exploit https://github.com/inspircd/inspircd/commit/6058483d9fbc1b904d5ae7cfea47bfcde5c5b559 Source: CONFIRM Type: Exploit https://github.com/inspircd/inspircd/issues/1033 Source: GENTOO Type: UNKNOWN GLSA-201512-13 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |