Summary: | <net-irc/irssi-0.8.20-r1: Heap corruption and missing boundary checks | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Matthew Thode ( prometheanfire ) <prometheanfire> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | monsieurp, swegener |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://irssi.org/security/irssi_sa_2016.txt | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Matthew Thode ( prometheanfire )
2016-09-21 19:55:31 UTC
arches, please quick stabilize =net-irc/irssi-0.8.20 for the bug @security - Not sure if it should be A3 or B3 amd64 stable x86 stable Stable on alpha. Stable for HPPA PPC64. sparc stable ppc stable arm stable ia64 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one. I think it'd have made more sense to stabilise -r1 since it includes another fix for another CVE (including the fix for the current bug). See bug 595172. Does someone mind if I mark -r1 stable via the ALLARCHES policy and clean up versions < -r1? so that we can kill two birds in one stone. I've just ported the keyword and performed a cleanup. No proofing of arbitrary code execution in this as mentioned by the CWE. Re-designating. GLSA Vote: No |