First published: Tue Oct 04 2011(Updated: )
The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protocol (CTCP) request, as demonstrated in the wild in September 2011.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quassel IRC | =0.4.0 | |
Quassel IRC | =0.3.1 | |
Quassel IRC | =0.3.0 | |
Quassel IRC | =0.5.0 | |
Quassel IRC | =0.5.2 | |
Quassel IRC | =0.7.1 | |
Quassel IRC | =0.4.3 | |
Quassel IRC | =0.4.1 | |
Quassel IRC | =0.5.1 | |
Quassel IRC | =0.7.0 | |
Quassel IRC | <=0.7.2 | |
Quassel IRC | =0.6.0 | |
Quassel IRC | =0.6.1 | |
Quassel IRC | =0.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3354 has been classified as a denial of service vulnerability with a critical impact on affected systems.
To fix CVE-2011-3354, upgrade to Quassel version 0.7.3 or later.
CVE-2011-3354 affects Quassel versions before 0.7.3, including 0.4.0, 0.3.1, 0.3.0, 0.5.0, 0.5.2, 0.7.1, 0.4.3, 0.4.1, 0.5.1, 0.7.0, 0.6.0, 0.6.1, and 0.4.2.
CVE-2011-3354 enables remote attackers to send crafted Client-To-Client Protocol requests leading to a denial of service.
CVE-2011-3354 was first demonstrated in the wild in September 2011.