kvirc 2:3.2.4-3ubuntu1.1 source package in Ubuntu

Changelog

kvirc (2:3.2.4-3ubuntu1.1) edgy-security; urgency=low

  * SECURITY UPDATE: parseIrcUrl() do not properly sanitize parts of the URI
    when building the command for KVIrc's internet script system. This can
    be exploited to inject and execute commands for the KVIrc script system
    (including the "run" command, which can be leveraged to execute shell
    commands) by e.g. tricking a user into opening a specially crafted
    "irc://" or similar URI.
  * Add debian/patches/09_parseIrcUrl_security_fix.patch: properly sanitizes
    URI strings, as done in upstream SVN. (Fixes LP: #123037)
  * References:
    - http://www.kvirc.net/?id=news&story=2007.06.29.22.00.1.story&dir=latest
    - http://secunia.com/secunia_research/2007-56/advisory/
    - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2951
    - https://svn.kvirc.de/kvirc/changeset/630/#file3 (fix to kvi_ircurl.cpp)

 -- <email address hidden> (Richard A. Johnson)   Mon, 02 Jul 2007 13:12:22 -0500

Upload details

Uploaded by:
Rich Johnson
Uploaded to:
Edgy
Original maintainer:
Robin Verduijn
Architectures:
any
Section:
net
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
kvirc_3.2.4.orig.tar.gz 7.4 MiB 115dcd30e27d165bfb408673004ad6711b1dbde625c2031566b0ace538cc95d9
kvirc_3.2.4-3ubuntu1.1.diff.gz 872.7 KiB ae4f748a121944c68d87354a5d835c160147162920501c136411376d61bd2de9
kvirc_3.2.4-3ubuntu1.1.dsc 673 bytes 68e275e3ca9b276f43005da7ac7cd4697c1d41ff8fe4417d5b97509cfad2aa77

View changes file

Binary packages built by this source

kvirc: No summary available for kvirc in ubuntu edgy.

No description available for kvirc in ubuntu edgy.

kvirc-data: No summary available for kvirc-data in ubuntu edgy.

No description available for kvirc-data in ubuntu edgy.

kvirc-dev: No summary available for kvirc-dev in ubuntu edgy.

No description available for kvirc-dev in ubuntu edgy.