Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 581658 (CVE-2016-4414) - <net-irc/quassel-0.12.4: Denial of Service (CVE-2016-4414)
Summary: <net-irc/quassel-0.12.4: Denial of Service (CVE-2016-4414)
Status: RESOLVED FIXED
Alias: CVE-2016-4414
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on: 579570
Blocks:
  Show dependency tree
 
Reported: 2016-04-30 16:34 UTC by Agostino Sarubbo
Modified: 2016-09-16 03:44 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-04-30 16:34:00 UTC
From ${URL} :

It was found that quasselcore is vulnerable to a denial of service
attack by unauthenticated clients. The protocol negotiation did not
take into account lack of a match, in which case
PeerFactory::createPeer returns a nullptr, which is immediately
dereferenced [1].
This issue was introduced in commit d1bf207 [2] (version 0.10.0 and
later), and fixed in commit e678873 [3] (tagged as version 0.12.4).

Can a CVE be assigned to this issue?

[1] https://github.com/quassel/quassel/blob/f64ac93/src/core/coreauthhandler.cpp#L100
[2] https://github.com/quassel/quassel/commit/d1bf207
[3] https://github.com/quassel/quassel/commit/e678873



@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Michael Palimaka (kensington) gentoo-dev 2016-09-14 16:58:37 UTC
Arch teams, please test and stabilise net-irc/quassel-0.12.4.

Target KEYWORDS="amd64 ppc x86".

Thanks!
Comment 2 Michael Palimaka (kensington) gentoo-dev 2016-09-14 17:02:55 UTC
(In reply to Michael Palimaka (kensington) from comment #1)
> Arch teams, please test and stabilise net-irc/quassel-0.12.4.
> 
> Target KEYWORDS="amd64 ppc x86".
> 
> Thanks!

Apologies for the noise, I didn't realise there was already a separate stabilisation bug.
Comment 3 Michael Palimaka (kensington) gentoo-dev 2016-09-14 17:19:14 UTC
Stabilisation and cleanup completed.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2016-09-16 03:44:52 UTC
Maintainer(s), Thank you for cleanup!

GLSA Vote: No
Closing noglsa.