CVE-2010-3443
published 2013-11-23CVE-2010-3443: ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.98%
78.3th percentile
ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | quassel | < quassel 0.7.1-1 (bookworm) | quassel 0.7.1-1 (bookworm) |
| quassel-irc | quassel | >= 0 < 0.7.1-1 | 0.7.1-1 |
| quassel-irc | quassel | >= 0 < 0.7.1-1 | 0.7.1-1 |
| quassel-irc | quassel | >= 0 < 0.7.1-1 | 0.7.1-1 |
| quassel-irc | quassel | >= 0 < 0.7.1-1 | 0.7.1-1 |
| quassel-irc | quassel_irc | <= 0.6.2 | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
| quassel-irc | quassel_irc | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-3443: quassel - ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote att...
vendor_debian·2010·CVSS 5.0
CVE-2010-3443 [MEDIUM] CVE-2010-3443: quassel - ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote att...
ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message.
Scope: local
bookworm: resolved (fixed in 0.7.1-1)
bullseye: resolved (fixed in 0.7.1-1)
forky: resolved (fixed in 0.7.1-1)
sid: resolved (fixed in 0.7.1-1)
trixie: resolved (fixed in 0.7.1-1)
GHSA
GHSA-gcm5-mx9r-f9mm: ctcphandler
ghsa_unreviewed·2022-05-17
CVE-2010-3443 [MEDIUM] GHSA-gcm5-mx9r-f9mm: ctcphandler
ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message.
OSV
CVE-2010-3443: ctcphandler
osv·2013-11-23·CVSS 5.0
CVE-2010-3443 [MEDIUM] CVE-2010-3443: ctcphandler
ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3443 quassel: multiple CTCP requests may lead to DoS [fedora-all]
bugzilla·2010-09-23·CVSS 5.0
CVE-2010-3443 [MEDIUM] CVE-2010-3443 quassel: multiple CTCP requests may lead to DoS [fedora-all]
CVE-2010-3443 quassel: multiple CTCP requests may lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=636942
Please note: this issue affects multiple
Bugzilla
CVE-2010-3443 quassel: multiple CTCP requests may lead to DoS
bugzilla·2010-09-23·CVSS 5.0
CVE-2010-3443 [MEDIUM] CVE-2010-3443 quassel: multiple CTCP requests may lead to DoS
CVE-2010-3443 quassel: multiple CTCP requests may lead to DoS
Quassel is vulnerable to a denial of service if it receives multiple CTCP requests in one PRIVMSG. The new version of Quassel (0.6.3 and 0.7) now answer with one packed NOTICE response containing all CTCP replies.
This affects Quassel as provided by Fedora.
References:
[1] http://quassel-irc.org/node/115
[2] http://bugs.quassel-irc.org/issues/1024
[3] http://bugs.quassel-irc.org/projects/quassel-irc/repository/revisions/fdec4a88742d1586a5fdfad767151c72a4a82af2/diff
Discussion:
Created quassel tracking bugs for this issue
Affects: fedora-all [bug 636944]
---
This has been assigned the name CVE-2010-3443.
---
This was reported over a month ago, and there is a bugfix release available that claims to fix this. Could the u
http://bugs.quassel-irc.org/issues/1023http://bugs.quassel-irc.org/issues/1024http://git.quassel-irc.org/?p=quassel.git%3Ba=commitdiff%3Bh=a4ca568cdf68cf4a0343eb161518dc8e50cea87dhttp://quassel-irc.org/node/115http://secunia.com/advisories/55581http://security.gentoo.org/glsa/glsa-201311-03.xmlhttp://ubuntu.com/usn/usn-991-1http://bugs.quassel-irc.org/issues/1023http://bugs.quassel-irc.org/issues/1024http://git.quassel-irc.org/?p=quassel.git%3Ba=commitdiff%3Bh=a4ca568cdf68cf4a0343eb161518dc8e50cea87dhttp://quassel-irc.org/node/115http://secunia.com/advisories/55581http://security.gentoo.org/glsa/glsa-201311-03.xmlhttp://ubuntu.com/usn/usn-991-1
2013-11-23
Published