Vulnerability Description
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quassel-Irc | Quassel | <= 0.10.0 |
| Opensuse | Leap | 42.1 |
| Opensuse | Opensuse | 13.1 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174938.ht
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174976.ht
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00099.html
- http://www.openwall.com/lists/oss-security/2015/12/12/1
- http://www.openwall.com/lists/oss-security/2015/12/13/1
- https://github.com/quassel/quassel/commit/b8edbda019eeb99da8663193e224efc9d1265dVendor Advisory
- https://github.com/quassel/quassel/pull/153
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174938.ht
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174976.ht
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00099.html
- http://www.openwall.com/lists/oss-security/2015/12/12/1
- http://www.openwall.com/lists/oss-security/2015/12/13/1
- https://github.com/quassel/quassel/commit/b8edbda019eeb99da8663193e224efc9d1265dVendor Advisory
- https://github.com/quassel/quassel/pull/153
FAQ
What is CVE-2015-8547?
CVE-2015-8547 is a vulnerability with a CVSS score of 7.5 (HIGH). The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query...
How severe is CVE-2015-8547?
CVE-2015-8547 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8547?
Check the references section above for vendor advisories and patch information. Affected products include: Quassel-Irc Quassel, Opensuse Leap, Opensuse Opensuse.