CVE-2015-2778: Medium severity quassel irc vulnerability
Published Apr 10, 2015
·Updated
Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters.
Affected Software
1 affected component
Quassel-irc Quassel<=0.11.0
Event History
Apr 10, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2778?
CVE-2015-2778 is classified as a denial of service vulnerability.
2
How do I fix CVE-2015-2778?
To fix CVE-2015-2778, upgrade to Quassel version 0.12-rc1 or later.
3
What types of attacks does CVE-2015-2778 enable?
CVE-2015-2778 enables remote attackers to crash the application using a long CTCP query.
4
Which versions of Quassel are affected by CVE-2015-2778?
Quassel versions prior to 0.12-rc1, specifically up to version 0.11.0, are affected by CVE-2015-2778.
5
What kind of characters trigger the vulnerability in CVE-2015-2778?
Multibyte characters within a long CTCP query can trigger the vulnerability in CVE-2015-2778.