CVE-2013-6404
Summary
| CVE | CVE-2013-6404 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-12-09 16:36:47 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/. |
Risk And Classification
Primary CVSS: v2.0 4 from [email protected]
AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS: 0.004470000 probability, percentile 0.635780000 (date 2026-04-29)
Problem Types: CWE-264 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Quassel-irc | Quassel Irc | 0.9.0 | All | All | All |
| Application | Quassel-irc | Quassel Irc | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Yet Another Important Update: Quassel 0.9.2 | Quassel IRC | af854a3a-2127-422b-91ae-364da2661108 | quassel-irc.org | Patch, Vendor Advisory |
| openSUSE-SU-2014:0114-1: moderate: update for quassel | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| osvdb.org/100432 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| oss-security - Re: CVE Request: Quassel IRC - manipulated clients can access backlog of all users on a shared core | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| openSUSE-SU-2013:1929-1: moderate: update for quassel | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Make sure that clients can't access buffers belonging to other users · quassel/quassel@a1a24da · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Security Advisory SA55640 - Quassel IRC Backlog Access Bypass Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.