First published: Sat Jan 22 2005(Updated: )
The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Konversation | =0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0131 is classified as a moderate severity vulnerability due to the potential for password leakage.
CVE-2005-0131 may lead to the exposure of user passwords to other users when connecting to an IRC server.
To mitigate CVE-2005-0131, upgrade to a version of Konversation newer than 0.15 or ensure that sensitive passwords are not used as nicknames.
CVE-2005-0131 is less of a concern today if users have updated their software to avoid the vulnerability.
CVE-2005-0131 specifically affects Konversation version 0.15.