[ubuntu/jaunty-security] irssi (delayed), irssi 0.8.12-6ubuntu1.2 (Accepted)

Ubuntu Installer archive at ubuntu.com
Fri Apr 16 00:03:31 BST 2010


irssi (0.8.12-6ubuntu1.2) jaunty-security; urgency=low

  * SECURITY UPDATE: perform certificate host validation
    - debian/patches/91_CVE-2010-1155.patch: adjust to verify hostname against
      CN. Also use one SSL_CTX per connection and use default trusted CAs if
      nothing specified.
    - CVE-2010-1155
  * SECURITY UPDATE: fix crash when checking for fuzzy nick match when not on
    the channel
    - debian/patches/91_CVE-2010-1156.patch: verify channel is non-NULL in
      src/core/nicklist.c
    - CVE-2010-1156
  * debian/patches/92_disable_sslv2.patch: do not use SSLv2 protocol

Date: Wed, 14 Apr 2010 15:43:34 -0500
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/jaunty/+source/irssi/0.8.12-6ubuntu1.2
-------------- next part --------------
Format: 1.8
Date: Wed, 14 Apr 2010 15:43:34 -0500
Source: irssi
Binary: irssi irssi-dev
Architecture: source
Version: 0.8.12-6ubuntu1.2
Distribution: jaunty-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 irssi      - terminal based IRC client
 irssi-dev  - text-mode version of the irssi IRC client development files
Changes: 
 irssi (0.8.12-6ubuntu1.2) jaunty-security; urgency=low
 .
   * SECURITY UPDATE: perform certificate host validation
     - debian/patches/91_CVE-2010-1155.patch: adjust to verify hostname against
       CN. Also use one SSL_CTX per connection and use default trusted CAs if
       nothing specified.
     - CVE-2010-1155
   * SECURITY UPDATE: fix crash when checking for fuzzy nick match when not on
     the channel
     - debian/patches/91_CVE-2010-1156.patch: verify channel is non-NULL in
       src/core/nicklist.c
     - CVE-2010-1156
   * debian/patches/92_disable_sslv2.patch: do not use SSLv2 protocol
Checksums-Sha1: 
 6a5e21f55944300a1e5285e09ad9a1854c734ab8 1391 irssi_0.8.12-6ubuntu1.2.dsc
 967538468183bf05f4df9faff47d11bbfd2ce690 24807 irssi_0.8.12-6ubuntu1.2.diff.gz
Checksums-Sha256: 
 bcd8e9b4b1129806d505a59436d83fc5f93e883b446c559f4bed1dc5fee4eb3b 1391 irssi_0.8.12-6ubuntu1.2.dsc
 7984426c92124e9e21064b9d7540107ca5c758aaadab4db3251049643ed5f6b6 24807 irssi_0.8.12-6ubuntu1.2.diff.gz
Files: 
 960eaacca58feaaa6291c03f4faa8848 1391 net optional irssi_0.8.12-6ubuntu1.2.dsc
 caae22ec37b9db5ade9c4b23215f6b82 24807 net optional irssi_0.8.12-6ubuntu1.2.diff.gz
Original-Maintainer: David Pashley <david at davidpashley.com>


More information about the Jaunty-changes mailing list