irssi (1.0.5-1ubuntu1) devel; urgency=medium * Merge from Debian. Remaining changes: - Refresh and re-enabled 20fix_ssl_proxy_hostname_check. - When we have a proxy setting, we expect the CN to match the proxy hostname, not the server hostname. - d/p/90irc-ubuntu-com: + Add the Ubuntu network with irc.ubuntu.com as the server, which is currently a CNAME for chat.freenode.net. - d/p/03firsttimer_text: + Adapt 03firsttimer_text so it tells you about connecting to Ubuntu and joining #ubuntu. * Changes no longer needed: - d/p/CVE-2017-15xxx.patch: Applied upstream. irssi (1.0.5-1) unstable; urgency=high * New upstream bugfix release (closes: #879521): - Fix missing -sasl_method '' in /NETWORK. - Fix incorrect restoration of term state when hitting SUSP inside screen. - Fix out of bounds read when compressing colour sequences. Found by Hanno Böck. [CVE-2017-15228] - Fix use after free condition during a race condition when waiting on channel sync during a rejoin [CVE-2017-15227] - Fix null pointer dereference when parsing certain malformed CTCP DCC messages. [CVE-2017-15721] - Fix crash due to null pointer dereference when failing to split messages due to overlong nick or target. [CVE-2017-15723] - Fix out of bounds read when trying to skip a safe channel ID without verifying that the ID is long enough. [CVE-2017-15722] - Fix return of random memory when inet_ntop failed. - Minor statusbar help update. * Remove deprecated --with autotools_dev call to dh. * Bump Standards-Version to 4.1.1. * Change priority of irssi-dev from deprecated extra to optional. * Use pkg-info.mk in debian/rules instead of calling dpkg-parsechangelog directly. -- Unit 193 <email address hidden> Sat, 02 Dec 2017 17:18:54 -0500