Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 891803 - <net-irc/ergo-2.11.1: Websocket denial of service issue
Summary: <net-irc/ergo-2.11.1: Websocket denial of service issue
Status: IN_PROGRESS
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://github.com/ergochat/ergo/pull...
Whiteboard: B3 [glsa?]
Keywords:
Depends on: 892155
Blocks:
  Show dependency tree
 
Reported: 2023-01-23 03:15 UTC by Sam James
Modified: 2023-02-03 12:20 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-01-23 03:15:34 UTC
Mentioned in 2.11.1 release notes:
"Fixed a denial-of-service issue affecting websocket clients (#2039)"

Bug: https://github.com/ergochat/ergo/pull/2039
Comment 1 Larry the Git Cow gentoo-dev 2023-01-23 03:17:21 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8b7d8f73227358965f743bfaccd12a13457128de

commit 8b7d8f73227358965f743bfaccd12a13457128de
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-01-23 03:16:28 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-01-23 03:16:28 +0000

    net-irc/ergo: add 2.11.1
    
    Bug: https://bugs.gentoo.org/891803
    Signed-off-by: Sam James <sam@gentoo.org>

 net-irc/ergo/Manifest           |  1 +
 net-irc/ergo/ergo-2.11.1.ebuild | 69 +++++++++++++++++++++++++++++++++++++++++
 2 files changed, 70 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2023-02-03 12:20:06 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d95a8d3beae82e11273968ca53b2ff1620a57707

commit d95a8d3beae82e11273968ca53b2ff1620a57707
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-02-03 12:19:06 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-02-03 12:19:06 +0000

    net-irc/ergo: drop 2.10.0-r1, 2.11.0
    
    Bug: https://bugs.gentoo.org/891803
    Signed-off-by: Sam James <sam@gentoo.org>

 net-irc/ergo/Manifest              |  2 --
 net-irc/ergo/ergo-2.10.0-r1.ebuild | 66 ------------------------------------
 net-irc/ergo/ergo-2.11.0.ebuild    | 69 --------------------------------------
 3 files changed, 137 deletions(-)