CVE-2016-4414: Null Pointer Dereference
Published Jun 13, 2016
·Updated
The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.
Affected Software
6 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Quassel-irc Quassel<=0.12.3
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Event History
Jun 13, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4414?
CVE-2016-4414 has a severity rating that indicates it can cause a denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2016-4414?
To fix CVE-2016-4414, upgrade Quassel to version 0.12.4 or later.
3
Which versions of Quassel are affected by CVE-2016-4414?
CVE-2016-4414 affects all versions of Quassel prior to 0.12.4.
4
What causes the vulnerability in CVE-2016-4414?
CVE-2016-4414 is caused by the onReadyRead function mishandling invalid handshake data.
5
Which operating systems are impacted by CVE-2016-4414?
CVE-2016-4414 impacts openSUSE Leap 42.1, openSUSE 13.2, and various versions of Fedora including 22, 23, and 24.