PT-2015-5890 · Quassel Irc+1 · Quassel+1
Pierre Schweitzer
·
Publicado
2015-04-10
·
Atualizado
2021-06-28
·
CVE-2015-2778
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Quassel versions prior to 0.12-rc1
Description
The issue allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters. This occurs because Quassel uses an incorrect data-type size when splitting a message.
Recommendations
For Quassel versions prior to 0.12-rc1, update to version 0.12-rc1 or later to resolve the issue. As a temporary workaround, consider restricting the length of CTCP queries to prevent the denial of service.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Quassel