Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks via a \ (backslash) in a message.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4422.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.debian.org/security/2015/dsa-3258 | |
| http://www.quassel-irc.org/node/127 | Vendor Advisory | 
| http://www.securityfocus.com/bid/74339 | 
Configurations
                    History
                    No history.
Information
                Published : 2015-05-14 14:59
Updated : 2016-12-06 03:00
NVD link : CVE-2015-3427
Mitre link : CVE-2015-3427
CVE.ORG link : CVE-2015-3427
JSON object : View
Products Affected
                debian
- debian_linux
 
quassel-irc
- quassel
 
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
