- added weechat-fix-hook_process-shell-injection.patch
which fixes a shell injection vulnerability in the
hook_process function (bnc#790217, CVE-2012-5534)
- added
weechat-fix-buffer-overflow-in-irc-color-decoding.patch
which fixes a heap-based overflow when decoding IRC
colors in strings (bnc#789146, CVE-2012-5854)
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.4/standard/i586/patchinfo.15:
zypper in -t patch 2012-9
To bring your system up-to-date, use "zypper patch".
- openSUSE 11.4/standard/i586/patchinfo.15 (i586 x86_64):
weechat-0.3.3-7.1
weechat-aspell-0.3.3-7.1
weechat-aspell-debuginfo-0.3.3-7.1
weechat-debuginfo-0.3.3-7.1
weechat-debugsource-0.3.3-7.1
weechat-devel-0.3.3-7.1
weechat-lua-0.3.3-7.1
weechat-lua-debuginfo-0.3.3-7.1
weechat-perl-0.3.3-7.1
weechat-perl-debuginfo-0.3.3-7.1
weechat-python-0.3.3-7.1
weechat-python-debuginfo-0.3.3-7.1
weechat-ruby-0.3.3-7.1
weechat-ruby-debuginfo-0.3.3-7.1
weechat-tcl-0.3.3-7.1
weechat-tcl-debuginfo-0.3.3-7.1
- openSUSE 11.4/standard/i586/patchinfo.15 (noarch):
weechat-lang-0.3.3-7.1
https://www.suse.com/security/cve/CVE-2012-5534.html
https://www.suse.com/security/cve/CVE-2012-5854.html
Get the latest Linux and open source security news straight to your inbox.