Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-12-09T11:00:00
Updated: 2024-08-06T17:39:01.300Z
Reserved: 2013-11-04T00:00:00
Link: CVE-2013-6404
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-12-09T16:36:47.283
Modified: 2024-11-21T01:59:09.630
Link: CVE-2013-6404
Redhat
No data.