Quassel IRC 'PRIVMSG' Remote Denial Of Service Vulnerability
BID:43476
Info
Quassel IRC 'PRIVMSG' Remote Denial Of Service Vulnerability
| Bugtraq ID: | 43476 |
| Class: | Unknown |
| CVE: |
CVE-2010-3443 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2010 12:00AM |
| Updated: | Mar 19 2015 08:26AM |
| Credit: | Jima |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.10 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 10.04 LTS |
| Not Vulnerable: | |
Discussion
Quassel IRC 'PRIVMSG' Remote Denial Of Service Vulnerability
Quassel IRC is prone to a remote denial-of-service vulnerability because it fails to properly handle 'CTCP' messages.
An attacker may exploit this issue to hang the application, resulting in a denial-of-service condition.
Versions prior to Quassel IRC 0.6.3 and 0.7.1 are vulnerable.
Quassel IRC is prone to a remote denial-of-service vulnerability because it fails to properly handle 'CTCP' messages.
An attacker may exploit this issue to hang the application, resulting in a denial-of-service condition.
Versions prior to Quassel IRC 0.6.3 and 0.7.1 are vulnerable.
Exploit / POC
Quassel IRC 'PRIVMSG' Remote Denial Of Service Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Quassel IRC 'PRIVMSG' Remote Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Quassel IRC 'PRIVMSG' Remote Denial Of Service Vulnerability
References:
References:
- Bug #1023 (Quassel IRC)
- Bug #1024 (Quassel IRC)
- Quassel IRC Homepage (Quassel IRC)