Bug 19458 - irssi new security issue CVE-2016-7553
Summary: irssi new security issue CVE-2016-7553
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/703245/
Whiteboard: MGA5-64-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-09-26 12:30 CEST by David Walser
Modified: 2016-11-18 00:41 CET (History)
6 users (show)

See Also:
Source RPM: irssi-0.8.20-1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-09-26 12:30:59 CEST
A CVE has been assigned for an issue fixed in the buf.pl file shipped with irssi:
http://www.openwall.com/lists/oss-security/2016/09/26/4
Comment 1 David Walser 2016-10-11 20:28:34 CEST
Fedora has issued an advisory for this on October 10:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3WUJ5QGF7IUNO3MJE76PYJHMHXYMAGNU/

URL: (none) => http://lwn.net/Vulnerabilities/703245/

Comment 2 Nicolas Lécureuil 2016-11-15 17:40:27 CET
SRPMS:   irssi-0.8.16-4.1.mga5

CC: (none) => mageia
Version: Cauldron => 5
Assignee: cooker => qa-bugs

Comment 3 Nicolas Lécureuil 2016-11-15 17:40:41 CET
fixed in mga5 updates
Comment 4 David Walser 2016-11-15 17:49:02 CET
Advisory:
========================

Updated irssi packages fix security vulnerability:

An information disclosure vulnerability was found in the buf.pl core script for
irssi. Other users on the same machine may be able to retrieve the whole window
contents after /UPGRADE when the buf.pl script is loaded. Furthermore, this dump
of the windows contents is never removed afterwards (CVE-2016-7553).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7553
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3WUJ5QGF7IUNO3MJE76PYJHMHXYMAGNU/
========================

Updated packages in core/updates_testing:
========================
irssi-0.8.16-4.1.mga5
irssi-perl-0.8.16-4.1.mga5
irssi-devel-0.8.16-4.1.mga5

from irssi-0.8.16-4.1.mga5.src.rpm
Comment 5 Nicolas Lécureuil 2016-11-16 09:27:06 CET
New Advisory:
========================

Updated irssi packages fix security vulnerability:

An information disclosure vulnerability was found in the buf.pl core script for
irssi. Other users on the same machine may be able to retrieve the whole window
contents after /UPGRADE when the buf.pl script is loaded. Furthermore, this dump
of the windows contents is never removed afterwards (CVE-2016-7553).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7553
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3WUJ5QGF7IUNO3MJE76PYJHMHXYMAGNU/
========================

Updated packages in core/updates_testing:
========================
irssi-0.8.20-1.mga5
irssi-perl-0.8.20-1.mga5
irssi-devel-0.8.20-1.mga5

from irssi-0.8.20.1.mga5.src.rpm
Comment 6 Len Lawrence 2016-11-17 12:12:29 CET
Installing this on x86_64.
Don't really understand the language used so leaving out any specific testing.  It is my preferred IRC client so it will be in use for tonight's meeting.

CC: (none) => tarazed25

Comment 7 Herman Viaene 2016-11-17 15:40:17 CET
MGA5-32 on AcerD620 Xfce
No installation issues
irssi launches from CLI and the help command works, leaving the rest to Len to OK.

CC: (none) => herman.viaene

Comment 8 Lewis Smith 2016-11-17 18:11:31 CET
(In reply to Herman Viaene from comment #7)
> MGA5-32 on AcerD620 Xfce
> No installation issues
> irssi launches from CLI and the help command works, leaving the rest to Len
> to OK.
Len is testing 64-bit. Are you able to do like him and use IRSSI, for 32-bit? If not, I will have a go.

CC: (none) => lewyssmith

Comment 9 Len Lawrence 2016-11-17 18:52:45 CET
Launched irssi from the command line and joined #mageia-qa and left again.  Leaving it online.  Shall validate it after the meeting.
Comment 10 Herman Viaene 2016-11-17 20:47:37 CET
@Lewis: no, I am not familiar at all with irssi, and have not enough time to masrer it before today's meeting.
Comment 11 Len Lawrence 2016-11-17 21:34:36 CET
Well the policy has been spelled out at the meeting so this can go on to updates.
Len Lawrence 2016-11-17 21:36:06 CET

Keywords: (none) => validated_update
Whiteboard: (none) => MGA5-64-OK
CC: (none) => sysadmin-bugs

Dave Hodgins 2016-11-17 21:42:48 CET

CC: (none) => davidwhodgins
Whiteboard: MGA5-64-OK => MGA5-64-OK advisory

Comment 12 Mageia Robot 2016-11-18 00:41:33 CET
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0384.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.