PublicDateAtUSN: 2018-05-08 15:29:00 UTC Candidate: CVE-2018-1000178 PublicDate: 2018-05-08 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000178 https://github.com/quassel/quassel/commit/2b777e99fc9f74d4ed21491710260664a1721d1f (master) https://github.com/quassel/quassel/commit/18389a713a6810f57ab237b945e8ee03df857b8b (0.12) http://www.openwall.com/lists/oss-security/2018/04/27/1 https://ubuntu.com/security/notices/USN-4594-1 Description: A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allows an attacker to execute code remotely. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=896914 https://bugs.launchpad.net/ubuntu/+source/quassel/+bug/1767539 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_quassel: upstream_quassel: released (1:0.12.5-1) precise/esm_quassel: DNE trusty_quassel: released (0.10.0-0ubuntu2.3) trusty/esm_quassel: DNE (trusty was released [0.10.0-0ubuntu2.3]) xenial_quassel: ignored (end of standard support, was needed) artful_quassel: ignored (reached end-of-life) bionic_quassel: released (1:0.12.4-3ubuntu1.18.04.3) cosmic_quassel: ignored (reached end-of-life) disco_quassel: ignored (reached end-of-life) eoan_quassel: not-affected (1:0.13.1-1ubuntu1.19.10.1) focal_quassel: not-affected (1:0.13.1-1ubuntu2) groovy_quassel: not-affected (1:0.13.1-1ubuntu2) hirsute_quassel: not-affected (1:0.13.1-1ubuntu2) impish_quassel: not-affected (1:0.13.1-1ubuntu2) jammy_quassel: not-affected (1:0.13.1-1ubuntu2) devel_quassel: not-affected (1:0.13.1-1ubuntu2)