Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE: 2022:0083-1 Moderate: Weechat Crash Issue Fix

opensuse
Calendar Grey March 18, 2022
Dist Opensuse Esm H88
openSUSE has released a Security Update for Weechat to address moderate vulnerability CVE-2021-40516 in the application.
An update that fixes one vulnerability is now available

Description

This update for weechat fixes the following issues:

update to 3.2.1:

* CVE-2021-40516: relay: fix crash when decoding a malformed websocket

frame (boo#1190206)

update to 3.2

main changes:

* use XDG directories by default (config, data, cache, runtime)

* add support of IRC SASL mechanisms SCRAM-SHA-1, SCRAM-SHA-256 and

SCRAM-SHA-512

* automatically load system certificates without giving a hardcoded path

to the file with certificates

* add options to customize commands executed on system signals received

(SIGHUP, SIGQUIT, SIGTERM, SIGUSR1, SIGUSR2)

* add bar item "tls_version" and buflist format

* add signals "cursor_start" and "cursor_end"

* add function crypto_hmac in API

* add translated string in evaluation of expressions with "translate:xxx"

* add info "weechat_daemon"

* add Python stub for WeeChat API

* add variables "${tg_shell_argc}" and "${tg_shell_argvN}" in command

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2022-83=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):

weechat-3.2.1-bp153.2.3.1

weechat-devel-3.2.1-bp153.2.3.1

weechat-lua-3.2.1-bp153.2.3.1

weechat-perl-3.2.1-bp153.2.3.1

weechat-python-3.2.1-bp153.2.3.1

weechat-ruby-3.2.1-bp153.2.3.1

weechat-spell-3.2.1-bp153.2.3.1

weechat-tcl-3.2.1-bp153.2.3.1

- openSUSE Backports SLE-15-SP3 (noarch):

weechat-lang-3.2.1-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2021-40516.html

https://bugzilla.suse.com/1190206

Announcement ID: openSUSE-SU-2022:0083-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here