Package "quassel"

Name: quassel


distributed IRC client - monolithic core+client

Latest version: 1:0.12.4-3ubuntu1.18.04.3
Release: bionic (18.04)
Level: security
Repository: universe
Homepage: https://www.quassel-irc.org


Download "quassel"

Other versions of "quassel" in Bionic

Repository Area Version
base universe 1:0.12.4-3ubuntu1
updates universe 1:0.12.4-3ubuntu1.18.04.3

Packages in group

Deleted packages are displayed in grey.


Version: 1:0.12.4-3ubuntu1.18.04.3 2020-10-20 20:07:12 UTC

  quassel (1:0.12.4-3ubuntu1.18.04.3) bionic-security; urgency=medium

  * Merge security patches from Debian.
  * SECURITY UPDATE: Remote code execution.
    - d/p/Implement_custom_deserializer.patch: Implement custom
      deserializer to add sanity checks.
    - CVE-2018-1000178
  * SECURITY UPDATE: NULL pointer dereference.
    - d/p/Reject_clients_that_attempt_to_login_before_the_core_is_configured.patch:
      this patch prevents it from crashing the core.
    - CVE-2018-1000179

 -- Eduardo Barretto <email address hidden> Mon, 19 Oct 2020 16:53:16 -0300

CVE-2018-1000178 Implement custom deserializer to add our own sanity checks
CVE-2018-1000179 Reject clients that attempt to login before the core is configured

About   -   Send Feedback to @ubuntu_updates