{"id":"MGASA-2013-0311","summary":"Updated quassel packages fix CVE-2013-4422","details":"Updated quassel packages fix security vulnerability:\n\nQuassel IRC before 0.9.1 is vulnerable to SQL injection if used with Qt\n4.8.5, due to a change in Qt's postgres driver, allowing other IRC users\nto trick the Quassel core into executing SQL queries (CVE-2013-4422).\n\nThis update provides Quassel 0.9.1, which fixes this and several other\nissues.\n","modified":"2026-04-16T06:22:56.019550117Z","published":"2013-10-17T19:49:10Z","upstream":["CVE-2013-4422"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0311.html"},{"type":"WEB","url":"http://quassel-irc.org/node/119"},{"type":"WEB","url":"http://quassel-irc.org/node/120"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11443"}],"affected":[{"package":{"name":"quassel","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/quassel?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.1-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0311.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}