| Summary: | irssi new security issue CVE-2019-13045 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | jani.valimaa, sysadmin-bugs, tarazed25 |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6TOO MGA7-64-OK MGA6-64-OK | ||
| Source RPM: | irssi-1.2.0-2.mga7.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 1.0.8 and 1.2.1 | ||
|
Description
David Walser
2019-06-30 17:22:58 CEST
David Walser
2019-06-30 17:23:11 CEST
Status comment:
(none) =>
Fixed upstream in 1.0.8 and 1.2.1 Pushed updated pkgs to core/updates_testing: irssi-1.0.8-1.mga6 for mga6 irssi-1.2.1-1.mga7 for mga7 Please test. CC:
(none) =>
jani.valimaa mga7, x86_64 Installed irssi and irssi-perl, checked it out then updated it. Started irssi again in the terminal, signed in to #mageia-meeting, posted a greeting then used /help to look at the commands available and tried out a few. All working as expected. Whiteboard:
MGA7TOO, MGA6TOO =>
MGA7TOO, MGA6TOO MGA7-64-OK mga6, x86_64 SASL not configured so immune to the bug. Login in a terminal using the irssi command and the existing .irssi/config file. Joined the #mageia-meeting channel at Freenode. Tried out /help and a few of the commands. No problems; /part, /quit. Whiteboard:
MGA7TOO, MGA6TOO MGA7-64-OK =>
MGA7TOO, MGA6TOO MGA7-64-OK MGA6-64-OK
David Walser
2019-07-04 17:06:36 CEST
Whiteboard:
MGA7TOO, MGA6TOO MGA7-64-OK MGA6-64-OK =>
MGA6TOO MGA7-64-OK MGA6-64-OK Advisory: ======================== Updated irssi package fixes security vulnerability: Irssi before 1.0.8 and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server (CVE-2019-13045). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13045 https://irssi.org/security/irssi_sa_2019_06.txt Advisory uploaded, validating. Keywords:
(none) =>
advisory, validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0206.html Status:
NEW =>
RESOLVED Ubuntu advisory for this from July 4, for reference: https://usn.ubuntu.com/4046-1/ |