Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4422

Опубликовано: 23 окт. 2013
Источник: debian
EPSS Низкий

Описание

SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
quasselfixed0.9.1-1package
quasselno-dsawheezypackage
quasselnot-affectedsqueezepackage

Примечания

  • Issue when used with Qt >= 4.8.5 and PostgreSQL >= 8.2

  • http://quassel-irc.org/node/120

  • http://bugs.quassel-irc.org/issues/1244

  • https://github.com/quassel/quassel/commit/aa1008be162cb27da938cce93ba533f54d228869

  • Caused by a change in Qt's postgres driver:

  • https://bugreports.qt-project.org/browse/QTBUG-30076

  • https://qt.gitorious.org/qt/qtbase/commit/e3c5351d06ce8a12f035cd0627356bc64d8c334a

EPSS

Процентиль: 70%
0.00671
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.

nvd
больше 11 лет назад

SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.

github
около 3 лет назад

SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.

EPSS

Процентиль: 70%
0.00671
Низкий