The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| atheme | atheme | 5.2.5 |
| atheme | atheme | 6.0.3 |
| atheme | atheme | 5.2.6 |
| atheme | atheme | 5.2.0 |
| atheme | atheme | 6.0.5 |
| atheme | atheme | 6.0.1 |
| atheme | atheme | 6.0.0 |
| atheme | atheme | 5.2.4 |
| atheme | atheme | 6.0.7 |
| atheme | atheme | 5.2.3 |
| atheme | atheme | 5.2.7 |
| atheme | atheme | 6.0.2 |
| atheme | atheme | 7.0.0 |
| atheme | atheme | 5.2.1 |
| atheme | atheme | 6.0.8 |
| atheme | atheme | 6.0.4 |
| atheme | atheme | 5.2.2 |
| atheme | atheme | 6.0.9 |
| atheme | atheme | 6.0.6 |
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| atheme | atheme | * |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.2 |
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| atheme | atheme | * |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.2 |
| debian | debian_linux | 8.0 |
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-772,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| atheme | atheme | 7.2.7 |