Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
[
{
"id": "CVE-2022-24976-65985416",
"source": "https://github.com/atheme/atheme/commit/4e664c75d0b280a052eb8b5e81aa41944e593c52",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "include/atheme/sasl.h"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"264181115141719115410501613210708693452",
"222754798231276678770365083454161360225",
"177285067101597845603528397864203774175",
"199054820762701691001989240818468296753"
]
},
"signature_type": "Line"
},
{
"id": "CVE-2022-24976-b076b9c9",
"source": "https://github.com/atheme/atheme/commit/4e664c75d0b280a052eb8b5e81aa41944e593c52",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "modules/saslserv/main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"181164004037616756640423420427750320372",
"313115584622875209309979514245591067323",
"178177798912038826071784961503266840049",
"92602061283873327545890553051924292853",
"77448892048842636663979471150463257294",
"245481455566510111142206612020968423652",
"1026313870649304281475816608592996698",
"5586248147490793460366759164049356703",
"270204745699703581546053686816737884482",
"38403516263160033101535605804046423711",
"145266275782670400238844850904385759748",
"90006946813639264304935864550855496921",
"71926987825986678306174984477597570288",
"171423761134648080727480061650639401911"
]
},
"signature_type": "Line"
}
]