{"id":"UBUNTU-CVE-2015-2778","details":"Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters.","modified":"2025-09-08T16:43:21Z","published":"2015-04-10T15:00:00Z","upstream":["CVE-2015-2778"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-2778"},{"type":"REPORT","url":"https://github.com/quassel/quassel/commit/b5e38970ffd55e2dd9f706ce75af9a8d7730b1b8"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2015/03/20/12"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2015/03/28/3"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2015/03/27/11"},{"type":"REPORT","url":"http://lists.opensuse.org/opensuse-updates/2015-04/msg00018.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2015-2778"}],"affected":[{"package":{"name":"quassel","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/quassel@0.10.0-0ubuntu2.2?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.0-0ubuntu2.2"}]}],"versions":["0.9.1-0ubuntu1","0.9.2-0ubuntu1","0.9.2-0ubuntu2","0.9.2-0ubuntu3","0.9.2-0ubuntu4","0.10~beta1-0ubuntu1","0.10~rc1-0ubuntu1","0.10.0-0ubuntu1","0.10.0-0ubuntu2","0.10.0-0ubuntu2.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"quassel","binary_version":"0.10.0-0ubuntu2.2"},{"binary_version":"0.10.0-0ubuntu2.2","binary_name":"quassel-client"},{"binary_version":"0.10.0-0ubuntu2.2","binary_name":"quassel-client-qt4"},{"binary_name":"quassel-core","binary_version":"0.10.0-0ubuntu2.2"},{"binary_name":"quassel-data","binary_version":"0.10.0-0ubuntu2.2"},{"binary_name":"quassel-qt4","binary_version":"0.10.0-0ubuntu2.2"},{"binary_name":"quassel-qt4-data","binary_version":"0.10.0-0ubuntu2.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-2778.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}