CVE-2018-1000179NULL Pointer Dereference in Quassel

Severity
7.5HIGHNVD
OSV9.8
EPSS
0.6%
top 31.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateMay 13

Description

A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an attacker to cause a denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/quassel< quassel 1:0.12.5-1 (bookworm)
Debianquassel-irc/quassel< 1:0.12.5-1+3
Ubuntuquassel-irc/quassel< 1:0.12.4-3ubuntu1.18.04.3

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-6mrg-x4pw-vhr6: A NULL Pointer Dereference of CWE-476 exists in quassel version 02022-05-13
OSV
quassel vulnerabilities2020-10-20
OSV
CVE-2018-1000179: A NULL Pointer Dereference of CWE-476 exists in quassel version 02018-05-08

📋Vendor Advisories

2
Ubuntu
Quassel vulnerabilities2020-10-20
Debian
CVE-2018-1000179: quassel - A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the qu...2018

💬Community

1
Bugzilla
quassel: multiple vulnerabilities fixed in 0.12.52018-04-30
CVE-2018-1000179 — NULL Pointer Dereference in Quassel | cvebase