Bug#506550: quassel: IRC client command injection vulnerability

2008-11-29 Thread Thomas Mueller
Am Samstag, 29. November 2008 schrieb Stefan Fritsch: > > New 0.2.0 packages containing the security patch will be available > > today. > > What is the status here? If you just lack a sponsor, just ask me or any > other security team member. > > Cheers, > Stefan Hi, Nico Golde has done the fix a

Bug#506550: quassel: IRC client command injection vulnerability

2008-11-29 Thread Stefan Fritsch
New 0.2.0 packages containing the security patch will be available today. What is the status here? If you just lack a sponsor, just ask me or any other security team member. Cheers, Stefan -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMA

Bug#506550: quassel: IRC client command injection vulnerability

2008-11-23 Thread Thomas Mueller
Am Sonntag, 23. November 2008 schrieb Moritz Muehlenhoff: > On Sat, Nov 22, 2008 at 03:13:43PM +0100, Eckhart Wörner wrote: > > Package: quassel > > Severity: grave > > Tags: security > > Justification: user security hole > > > > Quassel version in Debian is vulnerable to IRC command injection as >

Bug#506550: quassel: IRC client command injection vulnerability

2008-11-22 Thread Moritz Muehlenhoff
On Sat, Nov 22, 2008 at 03:13:43PM +0100, Eckhart Wörner wrote: > Package: quassel > Severity: grave > Tags: security > Justification: user security hole > > Quassel version in Debian is vulnerable to IRC command injection as described > in http://www.frsirt.com/english/advisories/2008/3164 > Upd

Bug#506550: quassel: IRC client command injection vulnerability

2008-11-22 Thread Eckhart Wörner
Actually the problem lies within quassel-core (same source package), stupid me. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#506550: quassel: IRC client command injection vulnerability

2008-11-22 Thread Eckhart Wörner
Package: quassel Severity: grave Tags: security Justification: user security hole Quassel version in Debian is vulnerable to IRC command injection as described in http://www.frsirt.com/english/advisories/2008/3164 Updated packages are already available at http://quassel.irc.org/ , according to q