CVE-2015-8547: High severity quassel irc vulnerability
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op " command in a query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8547?
CVE-2015-8547 has been classified as a denial of service vulnerability, allowing remote attackers to crash the application.
How do I fix CVE-2015-8547?
To fix CVE-2015-8547, update Quassel to a version later than 0.10.0 where the vulnerability has been patched.
Which software is affected by CVE-2015-8547?
CVE-2015-8547 affects Quassel IRC version 0.10.0 and specific versions of openSUSE.
Can CVE-2015-8547 lead to data loss?
While CVE-2015-8547 specifically causes a denial of service, it may lead to loss of unsaved data due to application crashes.
Is CVE-2015-8547 exploitable remotely?
Yes, CVE-2015-8547 can be exploited remotely by sending the specific command '/op *' to trigger an application crash.