CVE-2015-2778Quassel vulnerability

CWE-3995 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
1.6%
top 18.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 17

Description

Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/quassel< quassel 1:0.10.0-2.3 (bookworm)
Debianquassel-irc/quassel< 1:0.10.0-2.3+3

🔴Vulnerability Details

2
GHSA
GHSA-p62x-mmj3-75q4: Quassel before 02022-05-17
OSV
CVE-2015-2778: Quassel before 02015-04-10

📋Vendor Advisories

1
Debian
CVE-2015-2778: quassel - Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a messag...2015

💬Community

1
Bugzilla
CVE-2015-2778 quassel: core crash caused by sending an overlength CTCP query containing only multibyte characters.2015-03-23
CVE-2015-2778 — Debian Quassel vulnerability | cvebase