-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security]  irssi (SSA:2016-265-03)

New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1,
14.2, and -current to fix security issues.


Here are the details from the Slackware 14.2 ChangeLog:
+--------------------------+
patches/packages/irssi-0.8.20-i586-1_slack14.2.txz:  Upgraded.
  This update fixes two remote crash and heap corruption vulnerabilites
  in Irssi's format parsing code.  Impact:  Remote crash and heap
  corruption.  Remote code execution seems difficult since only Nuls are
  written.  Bugs discovered by, and patches provided by Gabriel Campana
  and Adrien Guinet from Quarkslab.
  For more information, see:
    https://irssi.org/security/irssi_sa_2016.txt
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7044
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7045
  (* Security fix *)
+--------------------------+


Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
(https://osuosl.org/) for donating FTP and rsync hosting
to the Slackware project!  :-)

Also see the "Get Slack" section on http://www.slackware.com/ for
additional mirror sites near you.

Updated package for Slackware 13.0:

Updated package for Slackware x86_64 13.0:

Updated package for Slackware 13.1:

Updated package for Slackware x86_64 13.1:

Updated package for Slackware 13.37:

Updated package for Slackware x86_64 13.37:

Updated package for Slackware 14.0:

Updated package for Slackware x86_64 14.0:

Updated package for Slackware 14.1:

Updated package for Slackware x86_64 14.1:

Updated package for Slackware 14.2:

Updated package for Slackware x86_64 14.2:

Updated package for Slackware -current:

Updated package for Slackware x86_64 -current:


MD5 signatures:
+-------------+

Slackware 13.0 package:
665e81f7d91b161e64b2be17cb2325fb  irssi-0.8.20-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
6376a86235a12cb99b6aa57e5d409832  irssi-0.8.20-x86_64-1_slack13.0.txz

Slackware 13.1 package:
c54dda80b48406f0bc861040ae869005  irssi-0.8.20-i486-1_slack13.1.txz

Slackware x86_64 13.1 package:
339a30b7ebb113bb9612e16d0a7c4f00  irssi-0.8.20-x86_64-1_slack13.1.txz

Slackware 13.37 package:
76f6674200c97e1a215dbd9420aad625  irssi-0.8.20-i486-1_slack13.37.txz

Slackware x86_64 13.37 package:
d95b1f8fa4a4ce91e8ddf61fbc2830fe  irssi-0.8.20-x86_64-1_slack13.37.txz

Slackware 14.0 package:
58679a36ec89a171cebfb59d1523df85  irssi-0.8.20-i486-1_slack14.0.txz

Slackware x86_64 14.0 package:
6dc5929f6b40b368e6942b17367ebb1c  irssi-0.8.20-x86_64-1_slack14.0.txz

Slackware 14.1 package:
58437a25c7acbe8164e330d3f2e829c0  irssi-0.8.20-i486-1_slack14.1.txz

Slackware x86_64 14.1 package:
7d4a59490d2c433602ab883f24ccc992  irssi-0.8.20-x86_64-1_slack14.1.txz

Slackware 14.2 package:
a6d28d443fcda0863f992c14e743fed0  irssi-0.8.20-i586-1_slack14.2.txz

Slackware x86_64 14.2 package:
ea9103ef46bf76bff69f4c73d6ede0e4  irssi-0.8.20-x86_64-1_slack14.2.txz

Slackware -current package:
5405a3503966826751e3467f5e13f80d  n/irssi-0.8.20-i586-1.txz

Slackware x86_64 -current package:
8b2cefb065193793356a74e6ae74d849  n/irssi-0.8.20-x86_64-1.txz


Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg irssi-0.8.20-i586-1_slack14.2.txz


+-----+

Slackware: 2016-265-03: irssi Security Update

September 21, 2016
New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues

Summary

Here are the details from the Slackware 14.2 ChangeLog: patches/packages/irssi-0.8.20-i586-1_slack14.2.txz: Upgraded. This update fixes two remote crash and heap corruption vulnerabilites in Irssi's format parsing code. Impact: Remote crash and heap corruption. Remote code execution seems difficult since only Nuls are written. Bugs discovered by, and patches provided by Gabriel Campana and Adrien Guinet from Quarkslab. For more information, see: https://irssi.org/security/irssi_sa_2016.txt https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7044 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7045 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 13.0 package: 665e81f7d91b161e64b2be17cb2325fb irssi-0.8.20-i486-1_slack13.0.txz
Slackware x86_64 13.0 package: 6376a86235a12cb99b6aa57e5d409832 irssi-0.8.20-x86_64-1_slack13.0.txz
Slackware 13.1 package: c54dda80b48406f0bc861040ae869005 irssi-0.8.20-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: 339a30b7ebb113bb9612e16d0a7c4f00 irssi-0.8.20-x86_64-1_slack13.1.txz
Slackware 13.37 package: 76f6674200c97e1a215dbd9420aad625 irssi-0.8.20-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: d95b1f8fa4a4ce91e8ddf61fbc2830fe irssi-0.8.20-x86_64-1_slack13.37.txz
Slackware 14.0 package: 58679a36ec89a171cebfb59d1523df85 irssi-0.8.20-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 6dc5929f6b40b368e6942b17367ebb1c irssi-0.8.20-x86_64-1_slack14.0.txz
Slackware 14.1 package: 58437a25c7acbe8164e330d3f2e829c0 irssi-0.8.20-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 7d4a59490d2c433602ab883f24ccc992 irssi-0.8.20-x86_64-1_slack14.1.txz
Slackware 14.2 package: a6d28d443fcda0863f992c14e743fed0 irssi-0.8.20-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: ea9103ef46bf76bff69f4c73d6ede0e4 irssi-0.8.20-x86_64-1_slack14.2.txz
Slackware -current package: 5405a3503966826751e3467f5e13f80d n/irssi-0.8.20-i586-1.txz
Slackware x86_64 -current package: 8b2cefb065193793356a74e6ae74d849 n/irssi-0.8.20-x86_64-1.txz

Severity
[slackware-security] irssi (SSA:2016-265-03)
New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg irssi-0.8.20-i586-1_slack14.2.txz

Related News