Lucene search

K
mageiaGentoo FoundationMGASA-2015-0147
HistoryApr 15, 2015 - 12:01 p.m.

Updated quassel packages fix security vulnerabilities

2015-04-1512:01:28
Gentoo Foundation
advisories.mageia.org
10

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.042 Low

EPSS

Percentile

92.3%

Updated quassel packages fix security vulnerabilities: Quassel could crash when receiving an overlength CTCP query containing only multibyte characters (CVE-2015-2778). Quassel could incorrectly split a message in the middle of a multibyte character, leading to a denial of service (CVE-2015-2779).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchquassel< 0.9.2-1.2quassel-0.9.2-1.2.mga4

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.042 Low

EPSS

Percentile

92.3%