CVE Database
/

CVE-2013-6404

Back to search

CVE-2013-6404

Published: Dec 9, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2013:1929
vendor-advisory
x_refsource_SUSE
55640
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2014:0114
vendor-advisory
x_refsource_SUSE
100432
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now