This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Quassel-Irc First view 2013-10-23
Product Quassel Irc Last view 2013-12-09
Version 0.7.2 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:quassel-irc:quassel_irc

Activity : Overall

Related : CVE

  Date Alert Description
4 2013-12-09 CVE-2013-6404

Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

6.8 2013-10-23 CVE-2013-4422

SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-264 Permissions, Privileges, and Access Controls
50% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...

Nessus® Vulnerability Scanner

id Description
2015-05-26 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2015-376.nasl - Type: ACT_GATHER_INFO
2015-05-18 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_49d9c28cfbad11e4b0fb00269ee29e57.nasl - Type: ACT_GATHER_INFO
2015-05-13 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3258.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2013-998.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2014-71.nasl - Type: ACT_GATHER_INFO
2014-02-27 Name: The remote Fedora host is missing a security update.
File: fedora_2014-1734.nasl - Type: ACT_GATHER_INFO
2014-02-27 Name: The remote Fedora host is missing a security update.
File: fedora_2014-1742.nasl - Type: ACT_GATHER_INFO
2013-11-07 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_f969bad746fc11e3b6ee00269ee29e57.nasl - Type: ACT_GATHER_INFO
2013-11-07 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201311-03.nasl - Type: ACT_GATHER_INFO