CVE-2013-6404 Information
Feb 14, 2021
cve
Description
Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs which allows remote authenticated users to read other users’ backlogs via the bufferid in (1) 16/select_buffer_by_id.sql (2) 16/select_buffer_by_id.sql and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.
Reference
http://lists.opensuse.org/opensuse-updates/2013-12/msg00092.html http://lists.opensuse.org/opensuse-updates/2014-01/msg00078.html http://osvdb.org/100432 http://quassel-irc.org/node/123 http://secunia.com/advisories/55640 http://www.openwall.com/lists/oss-security/2013/11/28/8 https://exchange.xforce.ibmcloud.com/vulnerabilities/89377 https://github.com/quassel/quassel/commit/a1a24da
Share on: