CVE-2018-1000178Out-of-bounds Write in Quassel

Severity
9.8CRITICALNVD
EPSS
1.1%
top 22.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateMay 13

Description

A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allows an attacker to execute code remotely.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/quassel< quassel 1:0.12.5-1 (bookworm)
Debianquassel-irc/quassel< 1:0.12.5-1+3
Ubuntuquassel-irc/quassel< 1:0.12.4-3ubuntu1.18.04.3

Also affects: Debian Linux 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h2q5-7v73-r3cx: A heap corruption of type CWE-120 exists in quassel version 02022-05-13
OSV
quassel vulnerabilities2020-10-20
OSV
CVE-2018-1000178: A heap corruption of type CWE-120 exists in quassel version 02018-05-08

📋Vendor Advisories

2
Ubuntu
Quassel vulnerabilities2020-10-20
Debian
CVE-2018-1000178: quassel - A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcor...2018

💬Community

1
Bugzilla
quassel: multiple vulnerabilities fixed in 0.12.52018-04-30
CVE-2018-1000178 — Out-of-bounds Write in Quassel | cvebase