CVE-2015-2779: Medium severity quassel irc vulnerability
Published Apr 10, 2015
·Updated
Stack consumption vulnerability in the message splitting functionality in Quassel before 0.12-rc1 allows remote attackers to cause a denial of service (uncontrolled recursion) via a crafted massage.
Affected Software
1 affected component
Quassel-irc Quassel<=0.11.0
Event History
Apr 10, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2779?
CVE-2015-2779 is classified as a denial of service vulnerability due to potential uncontrolled recursion leading to stack consumption.
2
How do I fix CVE-2015-2779?
To fix CVE-2015-2779, upgrade to Quassel version 0.12-rc1 or later.
3
What type of vulnerability is CVE-2015-2779?
CVE-2015-2779 is a stack consumption vulnerability related to message splitting functionality.
4
Which versions of Quassel are affected by CVE-2015-2779?
Quassel versions prior to 0.12-rc1, including all versions up to and including 0.11.0, are affected by CVE-2015-2779.
5
Can CVE-2015-2779 be exploited remotely?
Yes, CVE-2015-2779 can be exploited remotely by attackers through crafted messages.