Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T17:39:01.300Z
Reserved: 2013-11-04T00:00:00
Link: CVE-2013-6404

No data.

Status : Deferred
Published: 2013-12-09T16:36:47.283
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-6404

No data.