This repository has been archived by the owner on Feb 12, 2019. It is now read-only.
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
SASL: Disallow beginning : and space anywhere in AUTHENTICATE parameter
> This is a FIX FOR A SECURITY VULNERABILITY. All Charybdis users must > apply this fix if you support SASL on your servers, or unload m_sasl.so > in the meantime. Specifically, this is an issue in how SASL is handled in Charybdis-derived IRC daemons. The only practical attacks so far are to fraudlently log in as other services accounts using SASL EXTERNAL. There might be other vulnerabilities as a result of this, so it is best to apply this patch ASAP.
- Loading branch information