PT-2018-9348 · Quassel+1 · Quassel+1

Publicado

2018-05-02

·

Atualizado

2020-10-26

·

CVE-2018-1000178

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions quassel version 0.12.4
Description A heap corruption issue exists in the quasselcore component of quassel, specifically in the void DataStreamPeer::processMessage(const QByteArray &msg) function located in datastreampeer.cpp at line 62. This issue allows an attacker to execute code remotely.
Recommendations For quassel version 0.12.4, consider restricting access to the processMessage function in DataStreamPeer until a patch is available. As a temporary workaround, avoid using the quasselcore component if possible, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000178
DLA-1370-1
DSA-4189-1
MGASA-2018-0243
OPENSUSE-SU-2024:11291-1
USN-4594-1

Produtos afetados

Ubuntu
Quassel