First published: Tue May 08 2018(Updated: )
A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an attacker to cause a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/quassel | 1:0.13.1-1+deb10u2 1:0.13.1-5 1:0.14.0-1 1:0.14.0-2 | |
ubuntu/quassel | <1:0.12.4-3ubuntu1.18.04.3 | 1:0.12.4-3ubuntu1.18.04.3 |
ubuntu/quassel | <0.10.0-0ubuntu2.3 | 0.10.0-0ubuntu2.3 |
ubuntu/quassel | <1:0.12.5-1 | 1:0.12.5-1 |
Quassel IRC | =0.12.4 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000179 is classified as a denial of service vulnerability.
To fix CVE-2018-1000179, upgrade to quassel versions 0.12.5 or later, or the specific patched versions for Debian and Ubuntu listed in the advisory.
CVE-2018-1000179 affects quassel version 0.12.4 and prior, including various Debian and Ubuntu releases.
CVE-2018-1000179 is a NULL Pointer Dereference vulnerability identified by CWE-476.
CVE-2018-1000179 can lead to a denial of service, potentially crashing the quassel server.