CVE-2013-6404
N/A
N/A
Summary
Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://github.com/quassel/quassel/commit/a1a24da
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00092.html
- http://www.openwall.com/lists/oss-security/2013/11/28/8
- http://quassel-irc.org/node/123
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89377
- http://secunia.com/advisories/55640
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00078.html
- http://osvdb.org/100432
References
- https://github.com/quassel/quassel/commit/a1a24da
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00092.html
- http://www.openwall.com/lists/oss-security/2013/11/28/8
- http://quassel-irc.org/node/123
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89377
- http://secunia.com/advisories/55640
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00078.html
- http://osvdb.org/100432
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.