CVE-2005-0131: Medium severity BerliOS Konversation vulnerability
Published Jan 22, 2005
·Updated
The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.
Affected Software
1 affected component
BerliOS Konversation=0.15
Event History
Jan 22, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0131?
CVE-2005-0131 is classified as a moderate severity vulnerability due to the potential for password leakage.
2
How does CVE-2005-0131 affect users?
CVE-2005-0131 may lead to the exposure of user passwords to other users when connecting to an IRC server.
3
How do I fix CVE-2005-0131?
To mitigate CVE-2005-0131, upgrade to a version of Konversation newer than 0.15 or ensure that sensitive passwords are not used as nicknames.
4
Is CVE-2005-0131 still a concern today?
CVE-2005-0131 is less of a concern today if users have updated their software to avoid the vulnerability.
5
What software versions are affected by CVE-2005-0131?
CVE-2005-0131 specifically affects Konversation version 0.15.