Lucene search

K
mageiaGentoo FoundationMGASA-2013-0362
HistoryDec 01, 2013 - 1:42 a.m.

Updated quassel package fixes security vulnerability

2013-12-0101:42:15
Gentoo Foundation
advisories.mageia.org
17

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.004

Percentile

73.1%

Security vulnerability in Quassel before 0.9.2 through which a manipulated, but properly authenticated client was able to retrieve the backlog of other users on the same core in some cases (CVE-2013-6404).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchquassel< 0.9.2-1quassel-0.9.2-1.mga3

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.004

Percentile

73.1%