MGASA-2016-0166

Source
https://advisories.mageia.org/MGASA-2016-0166.html
Import Source
https://advisories.mageia.org/MGASA-2016-0166.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0166
Related
Published
2016-05-05T16:26:44Z
Modified
2016-05-05T16:20:08Z
Summary
Updated quassel packages fix CVE-2016-4414
Details

Updated quassel packages fix security vulnerability:

It was found that quasselcore is vulnerable to a denial of service attack by unauthenticated clients. The protocol negotiation did not take into account lack of a match in handshake data, in which case PeerFactory::createPeer returns a nullptr, which is immediately dereferenced (CVE-2016-4414).

References
Credits

Affected packages