The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing % variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Konversation | Berlios | 0.15 (including) | 0.15 (including) |
Konversation | Ubuntu | dapper | * |
Konversation | Ubuntu | devel | * |
Konversation | Ubuntu | edgy | * |
Konversation | Ubuntu | feisty | * |