The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing % variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Konversation | Berlios | 0.15 (including) | 0.15 (including) |
| Konversation | Ubuntu | dapper | * |
| Konversation | Ubuntu | devel | * |
| Konversation | Ubuntu | edgy | * |
| Konversation | Ubuntu | feisty | * |