First published: Thu Jun 17 2021(Updated: )
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quassel IRC | <=0.13.1 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34825 is rated as a moderate vulnerability due to the potential for unencrypted communication when SSL is required but not supported.
To fix CVE-2021-34825, ensure that a usable X.509 certificate is installed before launching Quassel with the --require-ssl option.
CVE-2021-34825 affects Quassel versions up to 0.13.1 and specific Fedora releases including version 33 and 34.
If no usable X.509 certificate is found, Quassel will launch without SSL or TLS support, exposing the communication.
A temporary workaround for CVE-2021-34825 is to remove the --require-ssl flag until an appropriate certificate is deployed.