{"id":"UBUNTU-CVE-2022-24976","details":"Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.","modified":"2026-05-20T16:07:51.251506773Z","published":"2022-02-14T12:15:00Z","upstream":["CVE-2022-24976"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-24976"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2022/01/30/4"},{"type":"REPORT","url":"https://github.com/atheme/atheme/commit/4e664c75d0b280a052eb8b5e81aa41944e593c52"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-24976"}],"affected":[{"package":{"name":"atheme-services","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/atheme-services?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.0.11-2","6.0.11-2+deb8u1build0.16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"atheme-services","binary_version":"6.0.11-2+deb8u1build0.16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-24976.json"}},{"package":{"name":"atheme-services","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/atheme-services?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.9-1","7.2.9-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"7.2.9-1build1","binary_name":"atheme-services"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-24976.json"}},{"package":{"name":"atheme-services","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/atheme-services?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.9-3"],"ecosystem_specific":{"binaries":[{"binary_name":"atheme-services","binary_version":"7.2.9-3"},{"binary_version":"7.2.9-3","binary_name":"atheme-services-contrib"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-24976.json"}},{"package":{"name":"atheme-services","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/atheme-services?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.11-1","7.2.11-1build1","7.2.12-1"],"ecosystem_specific":{"binaries":[{"binary_name":"atheme-services","binary_version":"7.2.12-1"},{"binary_name":"atheme-services-contrib","binary_version":"7.2.12-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-24976.json"}},{"package":{"name":"atheme-services","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/atheme-services?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.12-1","7.2.12-1build1","7.2.12-1build2"],"ecosystem_specific":{"binaries":[{"binary_version":"7.2.12-1build2","binary_name":"atheme-services"},{"binary_name":"atheme-services-contrib","binary_version":"7.2.12-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-24976.json"}},{"package":{"name":"atheme-services","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/atheme-services?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.12-2"],"ecosystem_specific":{"binaries":[{"binary_version":"7.2.12-2","binary_name":"atheme-services"},{"binary_version":"7.2.12-2","binary_name":"atheme-services-contrib"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-24976.json"}},{"package":{"name":"atheme-services","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/atheme-services?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.12-2"],"ecosystem_specific":{"binaries":[{"binary_name":"atheme-services","binary_version":"7.2.12-2"},{"binary_version":"7.2.12-2","binary_name":"atheme-services-contrib"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-24976.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}