FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

quassel -- multiple vulnerabilities

Affected packages
quassel < 0.12.5
quassel-core < 0.12.5

Details

VuXML ID 499f6b41-58db-4f98-b8e7-da8c18985eda
Discovery 2018-04-24
Entry 2018-04-26

Gentoo reports:

quasselcore: corruption of heap metadata caused by qdatastream leading to preauth remote code execution.

quasselcore DDOS

References

URL https://bugs.gentoo.org/653834
URL https://github.com/quassel/quassel/commit/08bace4e9ecf08273f094c0c6aa8b3363d38ac3e
URL https://github.com/quassel/quassel/commit/18389a713a6810f57ab237b945e8ee03df857b8b