PT-2018-9348 · Quassel+1 · Quassel+1

Published

2018-05-02

·

Updated

2020-10-26

·

CVE-2018-1000178

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions quassel version 0.12.4
Description A heap corruption issue exists in the quasselcore component of quassel, specifically in the void DataStreamPeer::processMessage(const QByteArray &msg) function located in datastreampeer.cpp at line 62. This issue allows an attacker to execute code remotely.
Recommendations For quassel version 0.12.4, consider restricting access to the processMessage function in DataStreamPeer until a patch is available. As a temporary workaround, avoid using the quasselcore component if possible, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000178
DLA-1370-1
DSA-4189-1
MGASA-2018-0243
OPENSUSE-SU-2024:11291-1
USN-4594-1

Affected Products

Ubuntu
Quassel