CVE-2015-3427 Information
Feb 14, 2021
cve
Description
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted which allows remote attackers to conduct SQL injection attacks via a \ (backslash) in a message. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4422.
Reference
http://www.debian.org/security/2015/dsa-3258 http://www.quassel-irc.org/node/127 http://www.securityfocus.com/bid/74339
Share on: