CVE-2016-7144: Unrealircd

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

Affected products

  • Unrealircd Unrealircd: up to and including 3.2.10.5; version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.3.1 only; …

Published 2017-01-18. Last modified 2026-06-17.