Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4414

Опубликовано: 13 июн. 2016
Источник: debian

Описание

The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
quasselfixed1:0.12.4-2package
quasselfixed1:0.10.0-2.3+deb8u3jessiepackage
quasselnot-affectedwheezypackage

Примечания

  • https://github.com/quassel/quassel/blob/f64ac93/src/core/coreauthhandler.cpp#L100

  • Introduced by: https://github.com/quassel/quassel/commit/d1bf207 (0.10.0)

  • Fixed by: https://github.com/quassel/quassel/commit/e67887343c433cc35bc26ad6a9392588f427e746 (0.12.4)

  • https://www.openwall.com/lists/oss-security/2016/04/30/2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.

CVSS3: 7.5
nvd
больше 9 лет назад

The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.

suse-cvrf
больше 9 лет назад

Security update for quassel

CVSS3: 7.5
github
больше 3 лет назад

The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.