Bug#896914: quassel: Implement custom deserializer to add our own sanity checks)

2018-04-27 Thread Scott Kitterman
I'm running the patched quassel core on Stretch and it is working fine. Scott K signature.asc Description: This is a digitally signed message part.

Bug#896914: quassel: Implement custom deserializer to add our own sanity checks

2018-04-25 Thread Salvatore Bonaccorso
Hi Felix! On Wed, Apr 25, 2018 at 11:28:53PM +0200, Felix Geyer wrote: > Hi, > > On Wed, 25 Apr 2018 20:58:52 +0200 Salvatore Bonaccorso > wrote: > > Source: quassel > > Version: 1:0.12.4-1 > > Severity: normal > > Tags: patch security upstream > > Control: fixed -1 1:0.12.5-1 > > > > Hi Felix

Bug#896914: [Pkg-kde-extras] Bug#896914: quassel: Implement custom deserializer to add our own sanity checks

2018-04-25 Thread Scott Kitterman
Issue descriptions from Gentoo (input for DSA text). I'm not sure issue 2 is really a security issue. Vuln 1: Title: quasselcore, corruption of heap metadata caused by qdatastream leading to preauth remote code execution. Severity: high, by default the server port is publicly open and the addres

Bug#896914: quassel: Implement custom deserializer to add our own sanity checks

2018-04-25 Thread Felix Geyer
Hi, On Wed, 25 Apr 2018 20:58:52 +0200 Salvatore Bonaccorso wrote: > Source: quassel > Version: 1:0.12.4-1 > Severity: normal > Tags: patch security upstream > Control: fixed -1 1:0.12.5-1 > > Hi Felix, > > Filling this as bug to have an identifier, since no CVE has been > assigned. > > https

Bug#896914: quassel: Implement custom deserializer to add our own sanity checks

2018-04-25 Thread Salvatore Bonaccorso
Source: quassel Version: 1:0.12.4-1 Severity: normal Tags: patch security upstream Control: fixed -1 1:0.12.5-1 Hi Felix, Filling this as bug to have an identifier, since no CVE has been assigned. https://www.quassel-irc.org/node/130 Commit "Implement custom deserializer to add our own sanity c