ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message.
References
| Link | Resource |
|---|---|
| http://ubuntu.com/usn/usn-991-1 | |
| http://security.gentoo.org/glsa/glsa-201311-03.xml | |
| http://bugs.quassel-irc.org/issues/1024 | Vendor Advisory |
| http://git.quassel-irc.org/?p=quassel.git;a=commitdiff;h=a4ca568cdf68cf4a0343eb161518dc8e50cea87d | Exploit Patch |
| http://quassel-irc.org/node/115 | Patch |
| http://bugs.quassel-irc.org/issues/1023 | Vendor Advisory |
| http://secunia.com/advisories/55581 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2013-11-23 11:55
Updated : 2014-03-05 18:48
NVD link : CVE-2010-3443
Mitre link : CVE-2010-3443
JSON object : View
Products Affected
quassel-irc
- quassel_irc
canonical
- ubuntu_linux
CWE
CWE-399
Resource Management Errors
