[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1089-1] irssi security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : irssi
Version        : 0.8.15-5+deb7u3
CVE ID         : CVE-2017-10965 CVE-2017-10966
Debian Bug     : 867598

Some Irssi issues were found:

CVE-2017-10965

	An issue was discovered in Irssi before 1.0.4. When receiving messages with
	invalid time stamps, Irssi would try to dereference a NULL pointer.

CVE-2017-10966

	An issue was discovered in Irssi before 1.0.4. While updating the internal
	nick list, Irssi could incorrectly use the GHashTable interface and free
	the nick while updating it. This would then result in use-after-free
	conditions on each access of the hash table.

For Debian 7 "Wheezy", these problems have been fixed in version
0.8.15-5+deb7u3.

We recommend that you upgrade your irssi packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEjtbD+LrJ23/BMKhw+COicpiDyXwFAlmuzJsACgkQ+COicpiD
yXyXpxAAhvhQ9x8tFS3Hrgibyl4ZX6K1Jn9E0Tf8ZTI7aZnhnPFsosNh+IFjcFwV
ptursGV4loC8Z0wt0qspfiOqfkYjenEuqHeNf4jNYJCtA13Dk+eDLKvDI1lUnVPF
99c1eiKa6hTI1iIYCOJYxmta3HKlhd/lRONAa64AUvfHHZWhMEAADjsaIUgAwHun
B+RL+EhgWYzfvMDvAfN7pBT3sHqJnHP6YxWuM/IzyOGlOADhsEL5wgQecrdR8qv7
T7T8UKSO1fFV/R26bfEZVJF0NL7l3GIwsN1i1qByP0c0CD2Vr2OdsPxj8PYTQhPO
9WO0n6lgc0dXGLGiavZCAPafNWaVQbsdtqekaSPRFQUWZ7wJTUb5ycAfTzqYUl8O
8or9MAea2DlXWmhvcDmjVxBk5bxOLfHzZ/94v2VlPTu920/Gndb7zw5uba7iCnWi
Pk3HlcIAsrHewJFQdRXbZg5y9YwqcRegtKEOW37vCDPqbkIN9id0XrMuKm7GHAC1
TaTIzRpxvxfyME3HPCqWBlbeFxHzMscxE7KGPaeYJ3MkHmcCFbhpu4HGvgV0nrDt
6e+V1ehnzPqaJ1Vl6/+aylt6BzDibBlF6+2IUslKzDHSX0Lg0aiDlHqA9qBtwf5B
Pc3l9mEn+BIH3i1FVwCWo1uIucexGPBDlvCf6pwXkBdu284iS5o=
=HsL1
-----END PGP SIGNATURE-----


Reply to: