CVE-2014-8483
published 2014-11-06CVE-2014-8483: The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.55%
88.0th percentile
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | konversation | < konversation 1.5-2 (bookworm) | konversation 1.5-2 (bookworm) |
| debian | quassel | < konversation 1.5-2 (bookworm) | konversation 1.5-2 (bookworm) |
| konversation | konversation | >= 0 < 1.5-2 | 1.5-2 |
| konversation | konversation | >= 0 < 1.5-2 | 1.5-2 |
| konversation | konversation | >= 0 < 1.5-2 | 1.5-2 |
| konversation | konversation | >= 0 < 1.5-2 | 1.5-2 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| quassel-irc | quassel | >= 0 < 0.10.0-2.1 | 0.10.0-2.1 |
| quassel-irc | quassel | >= 0 < 0.10.0-2.1 | 0.10.0-2.1 |
| quassel-irc | quassel | >= 0 < 0.10.0-2.1 | 0.10.0-2.1 |
| quassel-irc | quassel | >= 0 < 0.10.0-2.1 | 0.10.0-2.1 |
| quassel-irc | quassel_irc | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vgxr-2jwm-83q2: The blowfishECB function in core/cipher
ghsa_unreviewed·2022-05-14
CVE-2014-8483 [MEDIUM] CWE-125 GHSA-vgxr-2jwm-83q2: The blowfishECB function in core/cipher
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
OSV
CVE-2014-8483: The blowfishECB function in core/cipher
osv·2014-11-06·CVSS 5.0
CVE-2014-8483 [MEDIUM] CVE-2014-8483: The blowfishECB function in core/cipher
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
Ubuntu
Konversation vulnerability
vendor_ubuntu·2014-11-10
CVE-2014-8483 Konversation vulnerability
Title: Konversation vulnerability
Summary: Konversation could be made to crash if it received specially crafted
network traffic.
Manuel Nickschas discovered that Konversation did not properly perform
input sanitization when using Blowfish ECB encryption. A remote attacker
could exploit this to cause a denial of service.
Instructions: After a standard system update you need to restart Konversation to make
all the necessary changes.
Debian
CVE-2014-8483: konversation - The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote ...
vendor_debian·2014·CVSS 5.0
CVE-2014-8483 [MEDIUM] CVE-2014-8483: konversation - The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote ...
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
Scope: local
bookworm: resolved (fixed in 1.5-2)
bullseye: resolved (fixed in 1.5-2)
forky: resolved (fixed in 1.5-2)
sid: resolved (fixed in 1.5-2)
trixie: resolved (fixed in 1.5-2)
No detection rules found.
No public exploits indexed.
Bugzilla
konversation: out-of-bounds read flaw
bugzilla·2014-10-27·CVSS 5.0
[MEDIUM] konversation: out-of-bounds read flaw
konversation: out-of-bounds read flaw
An out-of-bounds read flaw was reported that affects Quassel (bug 1156418) and Konversation. A remote attacker could possibly use this flaw to cause Konversation to crash. This flaw could also leak memory.
References:
http://seclists.org/oss-sec/2014/q4/431
https://github.com/quassel/quassel/commit/8b5ecd226f9208af3074b33d3b7cf5e14f55b138
https://bugs.kde.org/show_bug.cgi?id=210792
Discussion:
Created attachment 950882
patch from upstream
---
Created konversation tracking bugs for this issue:
Affects: fedora-all [bug 1157342]
Affects: epel-all [bug 1157343]
---
MITRE assigned CVE-2014-8483 to these issues:
http://seclists.org/oss-sec/2014/q4/448
As the same CVE cannot alias more than one bug, I'm going to close this top level one and mark i
Bugzilla
CVE-2014-8483 quassel, konversation: out-of-bounds read on a heap-allocated array
bugzilla·2014-10-24·CVSS 5.0
CVE-2014-8483 [MEDIUM] CVE-2014-8483 quassel, konversation: out-of-bounds read on a heap-allocated array
CVE-2014-8483 quassel, konversation: out-of-bounds read on a heap-allocated array
It was reported [1] that there's an upstream commit [2] that fixes the issue [3] - it also fixes an out-of-bound read in quassel.
[1]: http://seclists.org/oss-sec/2014/q4/431
[2]: https://github.com/quassel/quassel/commit/8b5ecd226f9208af3074b33d3b7cf5e14f55b138
[3]: http://bugs.quassel-irc.org/issues/1314
Discussion:
Created quassel tracking bugs for this issue:
Affects: fedora-all [bug 1156420]
Affects: epel-all [bug 1156421]
---
MITRE assigned CVE-2014-8483 to this issue (including for Konversation, bug 1157341):
http://seclists.org/oss-sec/2014/q4/448
---
*** Bug 1157341 has been marked as a duplicate of this bug. ***
---
KDE's advisory:
https://www.kde.org/info/security/advisory-20141104-1.t
http://bugs.quassel-irc.org/issues/1314http://lists.opensuse.org/opensuse-updates/2014-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00046.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00068.htmlhttp://secunia.com/advisories/61932http://secunia.com/advisories/62035http://secunia.com/advisories/62261http://www.debian.org/security/2014/dsa-3063http://www.debian.org/security/2014/dsa-3068http://www.ubuntu.com/usn/USN-2401-1https://github.com/quassel/quassel/commit/8b5ecd226f9208af3074b33d3b7cf5e14f55b138http://bugs.quassel-irc.org/issues/1314http://lists.opensuse.org/opensuse-updates/2014-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00046.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00068.htmlhttp://secunia.com/advisories/61932http://secunia.com/advisories/62035http://secunia.com/advisories/62261http://www.debian.org/security/2014/dsa-3063http://www.debian.org/security/2014/dsa-3068http://www.ubuntu.com/usn/USN-2401-1https://github.com/quassel/quassel/commit/8b5ecd226f9208af3074b33d3b7cf5e14f55b138
2014-11-06
Published