Bug 25025 - irssi new security issue CVE-2019-13045
Summary: irssi new security issue CVE-2019-13045
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6TOO MGA7-64-OK MGA6-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-06-30 17:22 CEST by David Walser
Modified: 2019-08-11 23:22 CEST (History)
3 users (show)

See Also:
Source RPM: irssi-1.2.0-2.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 1.0.8 and 1.2.1


Attachments

Description David Walser 2019-06-30 17:22:58 CEST
Upstream has issued an advisory on June 29:
https://www.openwall.com/lists/oss-security/2019/06/29/1

The issue is fixed upstream in 1.0.8 and 1.2.1.

Mageia 6 is also affected.
David Walser 2019-06-30 17:23:11 CEST

Status comment: (none) => Fixed upstream in 1.0.8 and 1.2.1
Whiteboard: (none) => MGA7TOO, MGA6TOO

Comment 1 Jani Välimaa 2019-07-03 20:53:15 CEST
Pushed updated pkgs to core/updates_testing:
irssi-1.0.8-1.mga6 for mga6
irssi-1.2.1-1.mga7 for mga7

Please test.

CC: (none) => jani.valimaa
Assignee: jani.valimaa => qa-bugs

Comment 2 Len Lawrence 2019-07-04 16:09:12 CEST
mga7, x86_64
Installed irssi and irssi-perl, checked it out then updated it.
Started irssi again in the terminal, signed in to #mageia-meeting, posted a greeting then used /help to look at the commands available and tried out a few.  All working as expected.

Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO, MGA6TOO MGA7-64-OK
CC: (none) => tarazed25

Comment 3 Len Lawrence 2019-07-04 16:47:34 CEST
mga6, x86_64

SASL not configured so immune to the bug.
Login in a terminal using the irssi command and the existing .irssi/config file.
Joined the #mageia-meeting channel at Freenode.  Tried out /help and a few of the commands.

No problems; /part, /quit.

Whiteboard: MGA7TOO, MGA6TOO MGA7-64-OK => MGA7TOO, MGA6TOO MGA7-64-OK MGA6-64-OK

David Walser 2019-07-04 17:06:36 CEST

Whiteboard: MGA7TOO, MGA6TOO MGA7-64-OK MGA6-64-OK => MGA6TOO MGA7-64-OK MGA6-64-OK
Version: Cauldron => 7

Comment 4 David Walser 2019-07-04 20:31:50 CEST
Advisory:
========================

Updated irssi package fixes security vulnerability:

Irssi before 1.0.8 and 1.2.x before 1.2.1, when SASL is enabled, has a use
after free when sending SASL login to the server (CVE-2019-13045).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13045
https://irssi.org/security/irssi_sa_2019_06.txt
Comment 5 Rémi Verschelde 2019-07-10 11:32:17 CEST
Advisory uploaded, validating.

Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 6 Mageia Robot 2019-07-10 12:45:48 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0206.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 7 David Walser 2019-08-11 23:22:12 CEST
Ubuntu advisory for this from July 4, for reference:
https://usn.ubuntu.com/4046-1/

Note You need to log in before you can comment on or make changes to this bug.