CVE-2021-34825

Name
CVE-2021-34825
Description
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/quassel/quassel/pull/581
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZFWRN5P2WG23MWMVAEVV3YBHGFJHDSW/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JOFTSGJUJHCA3KGQBO6OZXWU7JFKVHMJ/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:quassel-irc:quassel:*:*:*:*:*:*:*:* quassel >= None <= 0.13.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
quassel 3.14-community 0.13.1-r6 Ariadne Conill <ariadne@dereferenced.org> fixed
quassel 3.15-community 0.13.1-r9 Ariadne Conill <ariadne@dereferenced.org> fixed