Lucene search

K
mageiaGentoo FoundationMGASA-2013-0311
HistoryOct 17, 2013 - 11:49 p.m.

Updated quassel packages fix CVE-2013-4422

2013-10-1723:49:10
Gentoo Foundation
advisories.mageia.org
8

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

72.4%

Updated quassel packages fix security vulnerability: Quassel IRC before 0.9.1 is vulnerable to SQL injection if used with Qt 4.8.5, due to a change in Qt’s postgres driver, allowing other IRC users to trick the Quassel core into executing SQL queries (CVE-2013-4422). This update provides Quassel 0.9.1, which fixes this and several other issues.

OSVersionArchitecturePackageVersionFilename
Mageia3noarchquassel< 0.9.1-1quassel-0.9.1-1.mga3

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

72.4%