CVE-2016-7143: Charybdis Project Charybdis
High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
Affected products
- Charybdis Project Charybdis: up to and including 3.5.2
- Debian Debian Linux: version 8.0 only
Published 2016-09-21. Last modified 2026-06-17.