An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd server by any user able to fully connect to a server.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20918.json"
[
{
"digest": {
"line_hashes": [
"137281295551576114536106547822918544856",
"294144551638259249213576490600158680981",
"258980650919900689067586385960914644667",
"158212954580586726344151970505063627189"
],
"threshold": 0.9
},
"id": "CVE-2019-20918-278ca253",
"source": "https://github.com/inspircd/inspircd/commit/7b47de3c194f239c5fea09a0e49696c9af017d51",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/modules/m_silence.cpp"
},
"signature_type": "Line"
}
]