CVE-2019-20917: Debian Linux

Medium severity, CVSS 6.5. EPSS: 2.8% chance of exploitation in the next 30 days.

An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Inspircd Inspircd: from 2.0, before 2.0.28 (fixed in 2.0.28); from 3.0, before 3.3.0 (fixed in 3.3.0)

Published 2020-09-11. Last modified 2026-06-17.