Security fixes from 0.12.5 require backfit to earlier releases
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
quassel (Debian) |
Fix Released
|
Unknown
|
|||
quassel (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
Trusty |
Fix Released
|
High
|
Steve Beattie | ||
Xenial |
Confirmed
|
High
|
Unassigned | ||
Bionic |
Confirmed
|
High
|
Unassigned | ||
Cosmic |
Fix Released
|
High
|
Unassigned |
Bug Description
A recent upstream release contains two security fixes. All supported Ubuntu releases are affected.
* SECURITY UPDATE: quasselcore, corruption of heap metadata caused by
qdatastream
- debian/
upstream 0.12.5 release, adapted for non-C++ 11 systems by Felix Geyer
- CVE requested by upstream
* SECURITY UPDATE: quasselcore, denial of service for unconfigure core
- debian/
_
for non-C++ 11 systems by Felix Geyer
- CVE requested by upstream
I'll be attaching a debdiff for Trusty, but not later releases as that is the only Ubuntu release I still have an interest in. Note that the debian/changelog doesn't have the LP bug number in it since I haven't filed it yet. The trusty fix is based on the Debian patches for Jessie (Debian 8):
https:/
I'm running the fixed version now.
CVE References
tags: | added: patch |
Changed in quassel (Debian): | |
status: | Unknown → Confirmed |
Changed in quassel (Ubuntu Xenial): | |
status: | New → Confirmed |
Changed in quassel (Ubuntu Bionic): | |
status: | New → Confirmed |
Changed in quassel (Ubuntu Artful): | |
status: | New → Confirmed |
Changed in quassel (Ubuntu Trusty): | |
importance: | Undecided → High |
assignee: | nobody → Simon Quigley (tsimonq2) |
Changed in quassel (Ubuntu Artful): | |
importance: | Undecided → High |
Changed in quassel (Ubuntu Bionic): | |
assignee: | nobody → Simon Quigley (tsimonq2) |
Changed in quassel (Ubuntu Xenial): | |
importance: | Undecided → High |
Changed in quassel (Ubuntu Bionic): | |
importance: | Undecided → High |
Changed in quassel (Ubuntu Xenial): | |
assignee: | nobody → Simon Quigley (tsimonq2) |
Changed in quassel (Ubuntu Artful): | |
assignee: | nobody → Simon Quigley (tsimonq2) |
Changed in quassel (Ubuntu Trusty): | |
assignee: | Scott Kitterman (kitterman) → Steve Beattie (sbeattie) |
Changed in quassel (Debian): | |
status: | Confirmed → Fix Released |
Changed in quassel (Ubuntu Xenial): | |
assignee: | Simon Quigley (tsimonq2) → nobody |
tags: | added: community-security |
no longer affects: | quassel (Ubuntu Artful) |
Changed in quassel (Ubuntu): | |
assignee: | Simon Quigley (tsimonq2) → nobody |
Changed in quassel (Ubuntu Cosmic): | |
assignee: | Simon Quigley (tsimonq2) → nobody |
Changed in quassel (Ubuntu Bionic): | |
assignee: | Simon Quigley (tsimonq2) → nobody |
Thanks Scott!
Subscribing the security sponsors.