CVE-2020-8955: backport 2.7.1 CVEs to 20.04 weechat-2.6

Bug #1872425 reported by TJ
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
weechat (Ubuntu)
Fix Released
Medium
TJ

Bug Description

Ensure latest CVEs fixed in 2.7.1 are included in 20.04

Tags: patch

CVE References

Revision history for this message
TJ (tj) wrote :

On recommendation of Sébastien Helleu a.k.a. FlashCode on IRC Freenode #weechat we should backport recent CVEs for 20.04 LTS:

$ gitlog v2.7..v2.7.1
5c0aa1aae 2020-02-20 20:45:08 +0100 N Sébastien Helleu Version 2.7.1
c827d6fa8 2020-02-14 08:14:31 +0100 N Sébastien Helleu irc: fix crash when receiving a malformed message 352 (who)
694b5c9f8 2020-02-14 08:11:02 +0100 N Sébastien Helleu irc: fix crash when a new message 005 is received with longer nick prefixes
51a739df6 2020-02-14 08:08:23 +0100 N Sébastien Helleu irc: fix crash when receiving a malformed message 324 (channel mode) (CVE-2020-8955)
410a12b2a 2020-02-14 08:05:19 +0100 N Sébastien Helleu Version 2.7.1-dev

I've added them on top of my earlier patch for LP #1866065 ("weechat python.so not linked against libpython3").

Changed in weechat (Ubuntu):
status: New → In Progress
assignee: nobody → TJ (tj)
summary: - CVEs: backport 2.7.1 CVEs to 20.04 weechat-2.6
+ CVE-2020-8955: backport 2.7.1 CVEs to 20.04 weechat-2.6
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "python3: correctly find and link against libpython3.8, CVE-2020-8955" seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are member of the ~ubuntu-sponsors, unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by ~brian-murray, for any issue please contact him.]

tags: added: patch
Mathew Hodson (mhodson)
information type: Public → Public Security
Changed in weechat (Ubuntu):
importance: Undecided → Medium
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package weechat - 2.6-2ubuntu2

---------------
weechat (2.6-2ubuntu2) focal; urgency=medium

  * Correctly find and link against libpython3.8 (LP: #1866065)
  * CVE-2020-8955 fix crashes when receiving malformed messages
    (LP: #1872425)

 -- Tj <email address hidden> Mon, 13 Apr 2020 10:21:33 +0100

Changed in weechat (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.