irssi 1.0.7-1ubuntu1 source package in Ubuntu

Changelog

irssi (1.0.7-1ubuntu1) cosmic; urgency=medium

  * Merge from Debian (LP: #1754781). Remaining changes:
    - Refresh and re-enabled 20fix_ssl_proxy_hostname_check.
      - When we have a proxy setting, we expect the CN to match
        the proxy hostname, not the server hostname.
    - d/p/90irc-ubuntu-com:
      + Add the Ubuntu network with irc.ubuntu.com as the server,
        which is currently a CNAME for chat.freenode.net.
    - d/p/03firsttimer_text:
      + Adapt 03firsttimer_text so it tells you about
        connecting to Ubuntu and joining #ubuntu.
  * Changes no longer needed:
    - d/p/CVE-2018-xxxx.patch: Applied upstream.

irssi (1.0.7-1) unstable; urgency=high

  * New upstream bugfix release (closes: #886475):
    From 1.0.6:
    - Fix invalid memory access when reading hilight configuration
      (#787, #788).
    - Fix null pointer dereference when the channel topic is set
      without specifying a sender [CVE-2018-5206]
    - Fix return of random memory when using incomplete escape
      codes [CVE-2018-5205]
    - Fix heap buffer overflow when completing certain strings
      [CVE-2018-5208]
    - Fix return of random memory when using an incomplete
      variable argument [CVE-2018-5207]

    From 1.0.7:
    - Prevent use after free error during the execution of some
      commands. Found by Joseph Bisch [CVE-2018-7054] (closes: #890674)
    - Revert netsplit print optimisation due to crashes
    - Fix use after free when SASL messages are received in
      unexpected order [CVE-2018-7053] (closes: #890675)
    - Fix null pointer dereference in the tab completion when an
      empty nick is joined [CVE-2018-7050] (closes: #890678)
    - Fix use after free when entering oper password
    - Fix null pointer dereference when too many windows are
      opened [CVE-2018-7052] (closes: #890676)
    - Fix out of bounds access in theme strings when the last
      escape is incomplete. Credit to Oss-Fuzz [CVE-2018-7051]
      (closes: #890677)
    - Fix out of bounds write when using negative counts on window
      resize
    - Minor help correction. By William Jackson

  * Fix watch URL.
  * Bump to debhelper compat 11, remove autotools-dev Build-Depends.
  * Bump Standards-Version to 4.1.3.
  * Add lintian overrides for the spelling of "hilight" in the changelog
    mentioning the lintian overrides for the spelling of "hilight" in irssi
    itself.

 -- Unit 193 <email address hidden>  Fri, 09 Mar 2018 17:54:53 -0500

Upload details

Uploaded by:
Unit 193
Sponsored by:
Gianfranco Costamagna
Uploaded to:
Cosmic
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
net
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
irssi_1.0.7.orig.tar.xz 1009.9 KiB 1b386ca026aa1875c380fd00ef1d24b71fb87cdae39ef5349ecca16c4567feac
irssi_1.0.7.orig.tar.xz.asc 1009.9 KiB 1b386ca026aa1875c380fd00ef1d24b71fb87cdae39ef5349ecca16c4567feac
irssi_1.0.7-1ubuntu1.debian.tar.xz 23.7 KiB 2748880bf0428525333bb6055b9f0944629c05e88c8835e8c5e128465f0ef619
irssi_1.0.7-1ubuntu1.dsc 2.2 KiB 21bb63f9c9129b9b52643502afc4934d1dd0168963dd4d399945022daf4a3cef

Available diffs

View changes file

Binary packages built by this source

irssi: No summary available for irssi in ubuntu cosmic.

No description available for irssi in ubuntu cosmic.

irssi-dbgsym: No summary available for irssi-dbgsym in ubuntu cosmic.

No description available for irssi-dbgsym in ubuntu cosmic.

irssi-dev: No summary available for irssi-dev in ubuntu cosmic.

No description available for irssi-dev in ubuntu cosmic.