DescriptionQuassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having low severity.
|National Vulnerability Database|
- openSUSE-SU-2013:1929-1, published Mon, 23 Dec 2013 15:05:11 +0100 (CET)
- openSUSE-SU-2014:0114-1, published Tue, 21 Jan 2014 16:04:13 +0100 (CET)
List of released packages
|Product(s)||Fixed package version(s)||References|
|openSUSE 13.1|| ||Patchnames: