5
CVSSv2

CVE-2015-2778

Published: 10/04/2015 Updated: 03/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Quassel prior to 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote malicious users to cause a denial of service (crash) via a long CTCP query containing only multibyte characters.

Vulnerable Product Search on Vulmon Subscribe to Product

quassel-irc quassel

Vendor Advisories

Debian Bug report logs - #781024 quassel: Denial of service (CVE-2015-2778 CVE-2015-2779) Package: quassel; Maintainer for quassel is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Source for quassel is src:quassel (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 23 ...