[v3.0] quassel: remote SQL injection (CVE-2015-3427)
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks via a \ (backslash) in a message. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4422.
http://seclists.org/oss-sec/2015/q2/291
CONFIRM: http://www.quassel-irc.org/node/127
http://www.debian.org/security/2015/dsa-3258
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3427
(from redmine: issue id 4220, created on 2015-05-22, closed on 2017-09-05)
- Relations:
- relates #4148 (closed)
- parent #4218