]> jfr.im git - irc/freenode/ircd-seven.git/commit
cherry-pick security fix from chary d06dab5
authorEd Kellett <redacted>
Sun, 4 Sep 2016 16:01:26 +0000 (16:01 +0000)
committerEd Kellett <redacted>
Sun, 4 Sep 2016 16:04:05 +0000 (16:04 +0000)
commit248ef2bd2b4a4ca5b603f98314482070d8b0cee1
treedae9d84a3f4aba70565f0f504be0502f7b9d1487
parentff41901bef18ac04cce05ffba9eddba13bf4b67f
cherry-pick security fix from chary d06dab5

SASL: Disallow beginning : and space anywhere in AUTHENTICATE parameter

This is a FIX FOR A SECURITY VULNERABILITY. All Charybdis users must
apply this fix if you support SASL on your servers, or unload m_sasl.so
in the meantime.
modules/m_sasl.c