CVE-2015-2779Quassel vulnerability

CWE-3995 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
1.7%
top 17.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 17

Description

Stack consumption vulnerability in the message splitting functionality in Quassel before 0.12-rc1 allows remote attackers to cause a denial of service (uncontrolled recursion) via a crafted massage.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/quassel< quassel 1:0.10.0-2.3 (bookworm)
Debianquassel-irc/quassel< 1:0.10.0-2.3+3

🔴Vulnerability Details

2
GHSA
GHSA-946w-76jw-c597: Stack consumption vulnerability in the message splitting functionality in Quassel before 02022-05-17
OSV
CVE-2015-2779: Stack consumption vulnerability in the message splitting functionality in Quassel before 02015-04-10

📋Vendor Advisories

1
Debian
CVE-2015-2779: quassel - Stack consumption vulnerability in the message splitting functionality in Quasse...2015

💬Community

1
Bugzilla
CVE-2015-2779 quassel: incorrect message splitting leading to DoS2015-03-24
CVE-2015-2779 — Debian Quassel vulnerability | cvebase