Quassel: Multiple Vulnerabilities Two vulnerabilities in Quassel may result in Denial of Service or SQL injection. quassel 2013-11-07 2013-11-07 338879 487632 remote 0.9.1 0.9.1

Quassel is a Qt4/KDE4 IRC client suppporting a remote daemon for 24/7 connectivity.

Two vulnerabilities have been found in Quassel:

A remote attacker could send multiple CTCP requests in single private message, possibly resulting in a Denial of Service condition. Futhermore, a remote attacker may be able to execute arbitrary SQL statements.

There is no known workaround at this time.

All Quassel users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-irc/quassel-0.9.1"
CVE-2010-3443 CVE-2013-4422 keytoaster ackle