Candidate: CVE-2015-8547 PublicDate: 2016-01-08 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8547 http://www.openwall.com/lists/oss-security/2015/12/12/1 Description: The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=807801 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_quassel: upstream: https://github.com/quassel/quassel/commit/b8edbda019eeb99da8663193e224efc9d1265dc7 upstream: https://github.com/quassel/quassel/commit/7ecbc1bf921880f7b03af779de7d9611853a0d46 (0.10-beta1) Tags_quassel: universe-binary upstream_quassel: released (1:0.12.2-3) precise_quassel: ignored (reached end-of-life) precise/esm_quassel: DNE (precise was needed) trusty_quassel: ignored (reached end-of-life) trusty/esm_quassel: DNE (trusty was needed) vivid_quassel: ignored (reached end-of-life) vivid/stable-phone-overlay_quassel: DNE vivid/ubuntu-core_quassel: DNE wily_quassel: ignored (reached end-of-life) xenial_quassel: ignored (end of standard support, was needed) yakkety_quassel: ignored (reached end-of-life) zesty_quassel: ignored (reached end-of-life) artful_quassel: not-affected (1:0.12.4-2ubuntu2) bionic_quassel: not-affected (1:0.12.4-2ubuntu2) cosmic_quassel: not-affected (1:0.12.4-2ubuntu2) disco_quassel: not-affected (1:0.12.4-2ubuntu2) eoan_quassel: not-affected (1:0.12.4-2ubuntu2) focal_quassel: not-affected (1:0.12.4-2ubuntu2) groovy_quassel: not-affected (1:0.12.4-2ubuntu2) hirsute_quassel: not-affected (1:0.12.4-2ubuntu2) impish_quassel: not-affected (1:0.12.4-2ubuntu2) jammy_quassel: not-affected (1:0.12.4-2ubuntu2) devel_quassel: not-affected (1:0.12.4-2ubuntu2)