CVE Vulnerabilities

CVE-2013-6404

Published: Dec 09, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

Affected Software

NameVendorStart VersionEnd Version
Quassel_ircQuassel-irc*0.9.1 (including)
Quassel_ircQuassel-irc0.9.0 (including)0.9.0 (including)
QuasselUbuntulucid*
QuasselUbuntuprecise*
QuasselUbuntuquantal*
QuasselUbunturaring*
QuasselUbuntusaucy*
QuasselUbuntuupstream*

References