modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade atheme-services | Jul 30, 2024 | Jun 13, 2016 |
| Freebsd | — | Upgrade atheme-services | Dec 10, 2025 | Dec 16, 2016 |
| Suse | — | Upgrade libathemecore1Upgrade libathemecore1-debuginfoUpgrade atheme-debugsourceUpgrade atheme-develUpgrade atheme-debuginfoUpgrade atheme | May 17, 2016 | May 17, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub