CVE-2018-1000178: Critical severity Quassel-irc Quassel vulnerability
Published May 8, 2018
·Updated
A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allows an attacker to execute code remotely.
Affected Software
5 affected componentsFixes available
Quassel-irc Quassel=0.12.4
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/quassel
1:0.13.1-51:0.14.0-11:0.14.0-31:0.14.0-4
Remediation
Event History
May 8, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 5, 2024
Data Sourced
via Launchpad·12:43 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·03:21 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:21 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-1000178?
CVE-2018-1000178 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2018-1000178?
To fix CVE-2018-1000178, upgrade Quassel to version 1:0.12.5-1 or later.
3
Which versions of Quassel are affected by CVE-2018-1000178?
CVE-2018-1000178 affects Quassel version 0.12.4 and earlier.
4
Can CVE-2018-1000178 be exploited remotely?
Yes, CVE-2018-1000178 allows an attacker to execute code remotely by exploiting heap corruption.
5
Is there any workaround for CVE-2018-1000178?
There are no known workarounds for CVE-2018-1000178; patching is the recommended approach.