USN-6761-1: Anope vulnerability
30 April 2024
Anope could be made to bypass authentication checks for suspended accounts.
Releases
Packages
- anope - an open source set of IRC Services
Details
It was discovered that Anope did not properly process credentials for
suspended accounts. An attacker could possibly use this issue to normally
login to the platform as a suspended user after changing their password.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 23.10
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
anope
-
2.0.4-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
anope
-
2.0.3-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.