CVE Vulnerabilities

CVE-2013-6404

Published: Dec 09, 2013 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

Affected Software

Name Vendor Start Version End Version
Quassel_irc Quassel-irc * 0.9.1 (including)
Quassel_irc Quassel-irc 0.9.0 (including) 0.9.0 (including)

References