← Back

Charybdis

charybdis

Vendor: Charybdis Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Charybdis Project
Debian
2Charybdis
Debian Linux
May 6, 2026
Sep 21, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.