5
CVSSv2

CVE-2016-4414

Published: 13/06/2016 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The onReadyRead function in core/coreauthhandler.cpp in Quassel prior to 0.12.4 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

opensuse opensuse 13.2

quassel-irc quassel

fedoraproject fedora 22

fedoraproject fedora 24

fedoraproject fedora 23

Vendor Advisories

Debian Bug report logs - #826402 quassel: CVE-2016-4414: remote DoS due to invalid handshake data Package: src:quassel; Maintainer for src:quassel is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Reported by: Pierre Schweitzer <pierre@reactosorg> Date: Sun, 5 Jun 2016 10:33:02 UTC Severity: norma ...