Описание
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| quassel | fixed | 1:0.12.2-3 | package | |
| quassel | fixed | 1:0.10.0-2.3+deb8u2 | jessie | package |
| quassel | not-affected | wheezy | package | |
| quassel | not-affected | squeeze | package |
Примечания
https://github.com/quassel/quassel/commit/b8edbda019eeb99da8663193e224efc9d1265dc7
Support for oping a whole channel with /op * was only added in
https://github.com/quassel/quassel/commit/7ecbc1bf921880f7b03af779de7d9611853a0d46 (0.10-beta1)
https://www.openwall.com/lists/oss-security/2015/12/12/1
EPSS
Связанные уязвимости
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.
EPSS