#1141625 inspircd: InspIRCd Security Advisory 2026-01: issues in ldapauth and ldapoper modules

Package:
src:inspircd
Source:
src:inspircd
Submitter:
Salvatore Bonaccorso
Date:
2026-07-24 14:13:02 UTC
Severity:
normal
Tags:
#1141625#5
Date:
2026-07-07 14:51:27 UTC
From:
To:
Hi

From https://docs.inspircd.org/security/2026-01/
| The LDAP modules before v4.11.0 do not escape user-provided values
| before using them in LDAP search filters. This vulnerability can be
| used to access an LDAP-restricted server (if ldapauth is used) or
| gain access to a LDAP-restricted operator account (if ldapoper is
| used) without knowing the correct username if the password of any
| user is known.

Fixes via
https://github.com/inspircd/inspircd/commit/b7e5357b144c2e20c72431e22f0f2b13e5be82ce
and
https://github.com/inspircd/inspircd/commit/6319ae4fb8c10dabc9464ad49faec532096fbcb5
.

Regards,
Salvatore

#1141625#10
Date:
2026-07-24 14:11:01 UTC
From:
To:
package release.debian.org
tags 1141625 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: sbsigntool
Version: 0.9.4-3.2+deb13u1

Explanation: fix intermediate certificate verification

#1141625#13
Date:
2026-07-24 14:11:01 UTC
From:
To:
package release.debian.org
tags 1141625 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: sbsigntool
Version: 0.9.4-3.2+deb13u1

Explanation: fix intermediate certificate verification