UbuntuUpdates.org

Package "quassel-client"

Name: quassel-client

Description:

distributed IRC client - client component

Latest version: 1:0.12.4-3ubuntu1.18.04.3
Release: bionic (18.04)
Level: security
Repository: universe
Head package: quassel
Homepage: https://www.quassel-irc.org

Links


Download "quassel-client"


Other versions of "quassel-client" in Bionic

Repository Area Version
base universe 1:0.12.4-3ubuntu1
updates universe 1:0.12.4-3ubuntu1.18.04.3

Changelog

Version: 1:0.12.4-3ubuntu1.18.04.3 2020-10-20 20:07:12 UTC

  quassel (1:0.12.4-3ubuntu1.18.04.3) bionic-security; urgency=medium

  * Merge security patches from Debian.
  * SECURITY UPDATE: Remote code execution.
    - d/p/Implement_custom_deserializer.patch: Implement custom
      deserializer to add sanity checks.
    - CVE-2018-1000178
  * SECURITY UPDATE: NULL pointer dereference.
    - d/p/Reject_clients_that_attempt_to_login_before_the_core_is_configured.patch:
      this patch prevents it from crashing the core.
    - CVE-2018-1000179

 -- Eduardo Barretto <email address hidden> Mon, 19 Oct 2020 16:53:16 -0300

CVE-2018-1000178 Implement custom deserializer to add our own sanity checks
CVE-2018-1000179 Reject clients that attempt to login before the core is configured



About   -   Send Feedback to @ubuntu_updates