The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
| Software | From | Fixed in |
|---|---|---|
| inspircd / inspircd | - | 2.0.22.x |
| debian / debian_linux | 8.0 | 8.0.x |