CVE Vulnerabilities

CVE-2013-6404

Published: Dec 09, 2013 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

Affected Software

Name Vendor Start Version End Version
Quassel_irc Quassel-irc * 0.9.1 (including)
Quassel_irc Quassel-irc 0.9.0 (including) 0.9.0 (including)
Quassel Ubuntu lucid *
Quassel Ubuntu precise *
Quassel Ubuntu quantal *
Quassel Ubuntu raring *
Quassel Ubuntu saucy *
Quassel Ubuntu upstream *

References