#1141625 inspircd: InspIRCd Security Advisory 2026-01: issues in ldapauth and ldapoper modules #1141625
- Package:
- src:inspircd
- Source:
- src:inspircd
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-24 14:13:02 UTC
- Severity:
- normal
- Tags:
Hi From https://docs.inspircd.org/security/2026-01/ | The LDAP modules before v4.11.0 do not escape user-provided values | before using them in LDAP search filters. This vulnerability can be | used to access an LDAP-restricted server (if ldapauth is used) or | gain access to a LDAP-restricted operator account (if ldapoper is | used) without knowing the correct username if the password of any | user is known. Fixes via https://github.com/inspircd/inspircd/commit/b7e5357b144c2e20c72431e22f0f2b13e5be82ce and https://github.com/inspircd/inspircd/commit/6319ae4fb8c10dabc9464ad49faec532096fbcb5 . Regards, Salvatore
package release.debian.org tags 1141625 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: sbsigntool Version: 0.9.4-3.2+deb13u1 Explanation: fix intermediate certificate verification
package release.debian.org tags 1141625 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: sbsigntool Version: 0.9.4-3.2+deb13u1 Explanation: fix intermediate certificate verification