Bug 29060 - irssi new security issues upstream in 1.2.3
Summary: irssi new security issues upstream in 1.2.3
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO MGA8-64-OK MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-05-31 00:05 CEST by David Walser
Modified: 2021-06-13 23:34 CEST (History)
7 users (show)

See Also:
Source RPM: irssi-1.2.2-3.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-05-31 00:05:10 CEST
openSUSE has issued an advisory on April 19:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IWZLMEBAAR5OLPQC7PWZHARHSMCZNVIM/

As the SUSE-bug says:
irssi 1.2.3 contains some security fixes.

* memory handling issues
* memory leaks
* erroneous free
* crashes / freezes
* null pointer dereference when receiving broken JOIN record

References:
https://irssi.org/2021/04/11/irssi-1.2.3-released/
https://irssi.org/NEWS/#v1-2-3
David Walser 2021-05-31 00:05:25 CEST

CC: (none) => geiger.david68210
Whiteboard: (none) => MGA7TOO
Assignee: bugsquad => jani.valimaa

Comment 1 Nicolas Lécureuil 2021-06-06 11:04:22 CEST
fixed in mga7/8

src:
    - mga7:
           - libnsl-1.3.0-1.mga7
           - irssi-1.2.3-1.mga7
    - mga8:
           - irssi-1.2.3-1.mga8

Assignee: jani.valimaa => qa-bugs
CC: (none) => mageia

Comment 2 Jani Välimaa 2021-06-06 12:16:04 CEST
I think importing libnsl to mga7 is a wrong approach as when mga7 was released libnsl.so was living in glibc-devel. Just remove 'pkgconfig(libnsl)' BR from mga7 irssi.

CC: (none) => jani.valimaa

Comment 3 Thomas Backlund 2021-06-06 12:39:53 CEST
yes, libnsl does not belong in Mageia 7
Comment 4 David Walser 2021-06-06 15:44:16 CEST
Assigning back to Nicholas as Mageia 7 isn't done.

Package list for Mageia 8:
irssi-1.2.3-1.mga8
irssi-perl-1.2.3-1.mga8
irssi-devel-1.2.3-1.mga8
irssi-otr-1.2.3-1.mga8

Assignee: qa-bugs => mageia

Comment 5 Nicolas Lécureuil 2021-06-06 19:20:59 CEST
fixing package list as it now builds.

fixed in mga7/8

src:
    - mga7:
           - irssi-1.2.3-1.mga7
    - mga8:
           - irssi-1.2.3-1.mga8
Nicolas Lécureuil 2021-06-06 19:21:09 CEST

Assignee: mageia => qa-bugs

Comment 6 David Walser 2021-06-06 20:35:13 CEST
RPMS for Mageia 7:
irssi-1.2.3-1.mga7
irssi-devel-1.2.3-1.mga7
irssi-perl-1.2.3-1.mga7
irssi-otr-1.2.3-1.mga7
Comment 7 Brian Rockwell 2021-06-08 19:27:53 CEST
The following 6 packages are going to be installed:

- irssi-1.2.3-1.mga8.x86_64
- irssi-devel-1.2.3-1.mga8.x86_64
- irssi-otr-1.2.3-1.mga8.x86_64
- irssi-perl-1.2.3-1.mga8.x86_64
- lib64otr5-4.1.1-3.mga8.x86_64
- lib64utf8proc2-2.6.1-1.mga8.x86_64

logged into freenode and #mageia
definitely sending commands and seeing transactions.

working

Whiteboard: MGA7TOO => MGA7TOO MGA8-64-OK
CC: (none) => brtians1

Comment 8 Brian Rockwell 2021-06-09 00:28:49 CEST
MGA7-64
The following 6 packages are going to be installed:

- irssi-1.2.3-1.mga7.x86_64
- irssi-devel-1.2.3-1.mga7.x86_64
- irssi-otr-1.2.3-1.mga7.x86_64
- irssi-perl-1.2.3-1.mga7.x86_64
- lib64otr5-4.1.1-2.mga7.x86_64
- lib64utf8proc2-2.3.0-1.mga7.x86_64

visited freenode #mageia

working as designed.

Whiteboard: MGA7TOO MGA8-64-OK => MGA7TOO MGA8-64-OK MGA7-64-OK

Comment 9 Thomas Andrews 2021-06-09 01:29:53 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 10 Aurelien Oudelet 2021-06-12 22:00:50 CEST
Advisory:
========================

Updated irssi packages fix security vulnerabilities

The irssi packages are updated to irssi 1.2.3 to fix several issues among some security vulnerabilities:

* memory handling issues
* memory leaks
* erroneous free
* crashes / freezes
* null pointer dereference when receiving broken JOIN record.

References:
https://bugs.mageia.org/show_bug.cgi?id=29060
https://irssi.org/2021/04/11/irssi-1.2.3-released/
https://irssi.org/NEWS/#v1-2-3
========================

Updated packages in 7/core/updates_testing:
========================
irssi-1.2.3-1.mga7
irssi-devel-1.2.3-1.mga7
irssi-perl-1.2.3-1.mga7
irssi-otr-1.2.3-1.mga7

from SRPM:
irssi-1.2.3-1.mga7.src.rpm

========================

Updated packages in 8/core/updates_testing:
========================
irssi-1.2.3-1.mga8
irssi-perl-1.2.3-1.mga8
irssi-devel-1.2.3-1.mga8
irssi-otr-1.2.3-1.mga8

from SRPM
irssi-1.2.3-1.mga8.src.rpm

CC: (none) => ouaurelien
Keywords: (none) => advisory

Comment 11 Mageia Robot 2021-06-13 23:34:50 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0255.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.