Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: MGASA-2021-0382 Critical: Quassel SSL Support Issue

mageia
Calendar Grey July 27, 2021
Dist Mageia Esm H88
The recent Quassel update addresses a significant SSL vulnerability in Mageia. Refer to the security advisory MGASA-2021-0382 to ensure your safety.
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825)

Summary

Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825).
Also, the default IRC server has been changed from Freenode to Libera Chat, as upstream has moved their #quassel channel there.

References

- https://bugs.mageia.org/show_bug.cgi?id=29193

- https://quassel-irc.org/node/136

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7ZFWRN5P2WG23MWMVAEVV3YBHGFJHDSW/

- https://www.cve.org/CVERecord?id=CVE-2021-34825

Resolution

SRPMS

- 8/core/quassel-0.13.1-6.2.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0382.html
Type: security
CVE: CVE-2021-34825

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here