cbcvebase.
CVE-2015-3427
published 2015-05-14

CVE-2015-3427: Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct…

PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.00%
78.5th percentile
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks via a \ (backslash) in a message. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4422.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianquassel< quassel 1:0.10.0-2.4 (bookworm)quassel 1:0.10.0-2.4 (bookworm)
quassel-ircquassel<= 0.12.1
quassel-ircquassel>= 0 < 1:0.10.0-2.41:0.10.0-2.4
quassel-ircquassel>= 0 < 1:0.10.0-2.41:0.10.0-2.4
quassel-ircquassel>= 0 < 1:0.10.0-2.41:0.10.0-2.4
quassel-ircquassel>= 0 < 1:0.10.0-2.41:0.10.0-2.4

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.