Quassel Core CTCP Ping Input Validation Vulnerability
BID:31973
Info
Quassel Core CTCP Ping Input Validation Vulnerability
| Bugtraq ID: | 31973 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5657 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | Wouter Coekaerts |
| Vulnerable: |
Quassel IRC Team Quassel Core 3.0.2 |
| Not Vulnerable: |
Quassel IRC Team Quassel Core 3.0.3 |
Discussion
Quassel Core CTCP Ping Input Validation Vulnerability
Quassel Core is prone to an input-validation issue that lets attackers hijack
An attacker may exploit this issue to execute arbitrary IRC commands as a user of the vulnerable application. This may aid in further attacks.
This issue exists in versions prior to Quassel Core 3.0.3.
Quassel Core is prone to an input-validation issue that lets attackers hijack
An attacker may exploit this issue to execute arbitrary IRC commands as a user of the vulnerable application. This may aid in further attacks.
This issue exists in versions prior to Quassel Core 3.0.3.
Exploit / POC
Quassel Core CTCP Ping Input Validation Vulnerability
An attacker may exploit this issue using commonly available tools.
An attacker may exploit this issue using commonly available tools.
Solution / Fix
Quassel Core CTCP Ping Input Validation Vulnerability
Solution:
The vendor has released an updated version; please see the references for more information.
Quassel IRC Team Quassel Core 3.0.2
Solution:
The vendor has released an updated version; please see the references for more information.
Quassel IRC Team Quassel Core 3.0.2
-
Quassel IRC Team quasselcore-0.3.0.3.exe
For Windows XP and Vista
http://quassel-irc.org/pub/quasselcore-0.3.0.3.exe -
Quassel IRC Team quasselcore-static-0.3.0.3.bz2
For Linux/x86
http://quassel-irc.org/pub/quasselcore-static-0.3.0.3.bz2 -
Quassel IRC Team QuasselCore_MacOSX-universal_0.3.0.3.dmg
For Mac OS/X
http://quassel-irc.org/pub/QuasselCore_MacOSX-universal_0.3.0.3.dmg
References
Quassel Core CTCP Ping Input Validation Vulnerability
References:
References:
- Quassel Homepage (Quassel IRC Team)
- Urgent: Security Upgrade! (Sputnick)
- Re: Quassel IRC: connection hijacking (Wouter Coekaerts
) - Quassel IRC: connection hijacking (Wouter Coekaerts
)