ArchLinux: 201711-19: konversation: denial of service
Summary
A denial of service vulnerability has been discovered in Konversation before 1.7.3 when handling colors in IRC messages. Any malicious user connected to the same IRC network could send a carefully crafted message that would crash the Konversation user client.
Resolution
Upgrade to 1.7.3-1.
# pacman -Syu "konversation>=1.7.3-1"
The problem has been fixed upstream in version 1.7.3.
References
https://kde.org/info/security/advisory-20171112-1.txt ;id=34cc9556c1a089fac6b674d3bd6f2248e9512902 https://security.archlinux.org/CVE-2017-15923
Workaround
Go to Interface -> Colors in the Configure Konversation dialog anduncheck Allow Colored Text in IRC Messages (near the bottom)