6.8
CVSSv2

CVE-2013-4422

Published: 23/10/2013 Updated: 16/06/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Quassel IRC prior to 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote malicious users to execute arbitrary SQL commands via a \ (backslash) in a message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

quassel-irc quassel_irc 0.6.3

quassel-irc quassel_irc 0.7.1

quassel-irc quassel_irc 0.4.1

quassel-irc quassel_irc 0.4.0

quassel-irc quassel_irc

quassel-irc quassel_irc 0.7.0

quassel-irc quassel_irc 0.6.2

quassel-irc quassel_irc 0.3.1

quassel-irc quassel_irc 0.3.0.3

quassel-irc quassel_irc 0.7.4

quassel-irc quassel_irc 0.8.0

quassel-irc quassel_irc 0.6.1

quassel-irc quassel_irc 0.5.0

quassel-irc quassel_irc 0.3.0.2

quassel-irc quassel_irc 0.3.0.1

quassel-irc quassel_irc 0.7.3

quassel-irc quassel_irc 0.7.2

quassel-irc quassel_irc 0.4.3

quassel-irc quassel_irc 0.4.2

quassel-irc quassel_irc 0.3.0

quassel-irc quassel_irc 0.1.0

Vendor Advisories

Debian Bug report logs - #783926 quassel: Incomplete fix for CVE-2013-4422 Package: src:quassel; Maintainer for src:quassel is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 1 May 2015 10:48:02 UTC Severity: important Tags: fixed-upst ...
It was discovered that the fix for CVE-2013-4422 in quassel, a distributed IRC client, was incomplete This could allow remote attackers to inject SQL queries after a database reconnection (eg when the backend PostgreSQL server is restarted) For the stable distribution (jessie), this problem has been fixed in version 1:0100-23+deb8u1 For the ...