CVE-2011-3354: Medium severity quassel irc vulnerability
The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protocol (CTCP) request, as demonstrated in the wild in September 2011.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3354?
CVE-2011-3354 has been classified as a denial of service vulnerability with a critical impact on affected systems.
How do I fix CVE-2011-3354?
To fix CVE-2011-3354, upgrade to Quassel version 0.7.3 or later.
Which versions of Quassel are affected by CVE-2011-3354?
CVE-2011-3354 affects Quassel versions before 0.7.3, including 0.4.0, 0.3.1, 0.3.0, 0.5.0, 0.5.2, 0.7.1, 0.4.3, 0.4.1, 0.5.1, 0.7.0, 0.6.0, 0.6.1, and 0.4.2.
What type of attack does CVE-2011-3354 facilitate?
CVE-2011-3354 enables remote attackers to send crafted Client-To-Client Protocol requests leading to a denial of service.
When was CVE-2011-3354 first demonstrated?
CVE-2011-3354 was first demonstrated in the wild in September 2011.