CVE-2013-4422
Publication date 23 October 2013
Last updated 24 July 2024
Ubuntu priority
SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.
Status
Package | Ubuntu Release | Status |
---|---|---|
quassel | ||
Notes
jdstrand
per upstream, "This bug was a introduced due to a bugfix in Qt 4.8.5 disables slash escaping when binding queries: https://bugreports.qt-project.org/browse/QTBUG-30076 Ubuntu 13.04 and earlier do not have Qt 4.8.5