CVE-2011-3354

The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protocol (CTCP) request, as demonstrated in the wild in September 2011.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
quassel-ircquassel
𝑥
≤ 0.7.2
quassel-ircquassel
0.3.0
quassel-ircquassel
0.3.1
quassel-ircquassel
0.4.0
quassel-ircquassel
0.4.1
quassel-ircquassel
0.4.2
quassel-ircquassel
0.4.3
quassel-ircquassel
0.5.0
quassel-ircquassel
0.5.1
quassel-ircquassel
0.5.2
quassel-ircquassel
0.6.0
quassel-ircquassel
0.6.1
quassel-ircquassel
0.7.0
quassel-ircquassel
0.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
quassel
bullseye
1:0.13.1-5
fixed
bookworm
1:0.14.0-1
fixed
sid
1:0.14.0-2
fixed
trixie
1:0.14.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
quassel
natty
Fixed 0.7.2-0ubuntu2.2
released
maverick
Fixed 0.7.1-0ubuntu1.1
released
lucid
Fixed 0.6.1-0ubuntu1.2
released
hardy
dne
Common Weakness Enumeration