5

CVE-2011-3354

The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protocol (CTCP) request, as demonstrated in the wild in September 2011.

Data is provided by the National Vulnerability Database (NVD)
Quassel-ircQuassel Version <= 0.7.2
Quassel-ircQuassel Version0.3.0
Quassel-ircQuassel Version0.3.1
Quassel-ircQuassel Version0.4.0
Quassel-ircQuassel Version0.4.1
Quassel-ircQuassel Version0.4.2
Quassel-ircQuassel Version0.4.3
Quassel-ircQuassel Version0.5.0
Quassel-ircQuassel Version0.5.1
Quassel-ircQuassel Version0.5.2
Quassel-ircQuassel Version0.6.0
Quassel-ircQuassel Version0.6.1
Quassel-ircQuassel Version0.7.0
Quassel-ircQuassel Version0.7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.62% 0.802
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P