cbcvebase.
CVE-2015-2778
published 2015-04-10

CVE-2015-2778: Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a…

PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.65%
83.9th percentile
Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianquassel< quassel 1:0.10.0-2.3 (bookworm)quassel 1:0.10.0-2.3 (bookworm)
quassel-ircquassel<= 0.11.0
quassel-ircquassel>= 0 < 1:0.10.0-2.31:0.10.0-2.3
quassel-ircquassel>= 0 < 1:0.10.0-2.31:0.10.0-2.3
quassel-ircquassel>= 0 < 1:0.10.0-2.31:0.10.0-2.3
quassel-ircquassel>= 0 < 1:0.10.0-2.31:0.10.0-2.3

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.