You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa irssi

Sigurnosni nedostaci programskog paketa irssi

——————————————————————————–
Fedora Update Notification
FEDORA-2018-c4e4935e01
2018-01-17 14:43:41.390782
——————————————————————————–

Name : irssi
Product : Fedora 27
Version : 1.0.6
Release : 1.fc27
URL : http://irssi.org/
Summary : Modular text mode IRC client with Perl scripting
Description :
Irssi is a modular IRC client with Perl scripting. Only text-mode
frontend is currently supported. The GTK/GNOME frontend is no longer
being maintained.

——————————————————————————–
Update Information:

This is new version of irssi. It contains security fixes for CVE-2018-5205
CVE-2018-5206 CVE-2018-5207 CVE-2018-5208 .
——————————————————————————–
References:

[ 1 ] Bug #1532624 – CVE-2018-5207 irssi: Out-of-bounds read when using an incomplete variable argument
https://bugzilla.redhat.com/show_bug.cgi?id=1532624
[ 2 ] Bug #1532622 – CVE-2018-5208 irssi: heap buffer overflow due to calculation error in the completion code
https://bugzilla.redhat.com/show_bug.cgi?id=1532622
[ 3 ] Bug #1532573 – CVE-2018-5205 irssi: Out-of-bounds read when using incomplete escape codes
https://bugzilla.redhat.com/show_bug.cgi?id=1532573
[ 4 ] Bug #1532569 – CVE-2018-5206 irssi: NULL pointer dereference when channel topic is set without specifying sender
https://bugzilla.redhat.com/show_bug.cgi?id=1532569
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade irssi’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2018-bc08435961
2018-01-17 14:43:36.646286
——————————————————————————–

Name : irssi
Product : Fedora 26
Version : 1.0.6
Release : 1.fc26
URL : http://irssi.org/
Summary : Modular text mode IRC client with Perl scripting
Description :
Irssi is a modular IRC client with Perl scripting. Only text-mode
frontend is currently supported. The GTK/GNOME frontend is no longer
being maintained.

——————————————————————————–
Update Information:

This is new version of irssi. It contains security fixes for CVE-2018-5205
CVE-2018-5206 CVE-2018-5207 CVE-2018-5208.
——————————————————————————–
References:

[ 1 ] Bug #1532624 – CVE-2018-5207 irssi: Out-of-bounds read when using an incomplete variable argument
https://bugzilla.redhat.com/show_bug.cgi?id=1532624
[ 2 ] Bug #1532622 – CVE-2018-5208 irssi: heap buffer overflow due to calculation error in the completion code
https://bugzilla.redhat.com/show_bug.cgi?id=1532622
[ 3 ] Bug #1532573 – CVE-2018-5205 irssi: Out-of-bounds read when using incomplete escape codes
https://bugzilla.redhat.com/show_bug.cgi?id=1532573
[ 4 ] Bug #1532569 – CVE-2018-5206 irssi: NULL pointer dereference when channel topic is set without specifying sender
https://bugzilla.redhat.com/show_bug.cgi?id=1532569
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade irssi’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Top
More in Preporuke
Sigurnosni nedostaci programskog paketa bind9

Otkriveni su sigurnosni nedostaci u programskom paketu bind9 za operacijski sustav Ubuntu. Otkriveni nedostaci potencijalnim napadačima omogućuju rušenje aplikacije i...

Close