It was discovered that there was a denial of service vulnerability in the konversation IRC client related to parsing of color formatting codes. For Debian 7 "Wheezy", this issue has been fixed in konversation version . Hash: SHA256 Package : konversation Version : 1.4-1+deb7u2 CVE ID : CVE-2017-15923 Debian Bug : #881586 It was discovered that there was a denial of service vulnerability in the konversation IRC client related to parsing of color formatting codes. For Debian 7 "Wheezy", this issue has been fixed in konversation version 1.4-1+deb7u2. We recommend that you upgrade your konversation packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
The package konversation before version 1.7.3-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201711-19 ========================================= Severity: Medium Date : 2017-11-12 CVE-ID : CVE-2017-15923 Package : konversation Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-489 Summary ====== The package konversation before version 1.7.3-1 is vulnerable to denial of service. Resolution ========= Upgrade to 1.7.3-1. # pacman -Syu "konversation> =1.7.3-1" The problem has been fixed upstream in version 1.7.3. Workaround ========= Go to Interface -> Colors in the Configure Konversation dialog and uncheck Allow Colored Text in IRC Messages (near the bottom) Description ========== A denial of service vulnerability has been discovered in Konversation before 1.7.3 when handling colors in IRC messages. Any malicious user connected to the same IRC network could send a carefully crafted message that would crash the Konversation user client. Impact ===== A remote attacker is able to craft messages that can result in the client crashing. References ========= https://kde.org/info/security/advisory-20171112-1.txt ;id=34cc9556c1a089fac6b674d3bd6f2248e9512902 https://security.archlinux.org/CVE-2017-15923 . Arch Linux Security Bulletin ASA-202310-36 Highlights a Moderate Severity KDE Connect Denial Of Service Vulnerability.. Arch Linux, Konversation, Denial Of Service, Security Advisory, Medium Severity. . Severity: Medium. LinuxSecurity.com Team
Konversation could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-2401-1 November 10, 2014 konversation vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Konversation could be made to crash if it received specially crafted network traffic. Software Description: - konversation: Internet Relay Chat (IRC) client for KDE Details: Manuel Nickschas discovered that Konversation did not properly perform input sanitization when using Blowfish ECB encryption. A remote attacker could exploit this to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: konversation 1.4-1ubuntu2.1 After a standard system update you need to restart Konversation to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2401-1 CVE-2014-8483 Package Information: https://launchpad.net/ubuntu/+source/konversation/1.4-1ubuntu2.1 . Follow these steps to update Ubuntu 12.04 LTS and address the Konversation crash vulnerability caused by malformed network traffic Ensure your system remains secure. Konversation, Ubuntu 12.04, Denial of Service, Network Exploit. . LinuxSecurity.com Team
The package konversation before version 1.5.1-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201411-5 ======================================== Severity: Low Date : 2014-11-09 CVE-ID : CVE-2014-8483 Package : konversation Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/title/CVE-2014 Summary ====== The package konversation before version 1.5.1-1 is vulnerable to denial of service. Resolution ========= Upgrade to 1.5.1-1. # pacman -Syu "konversation> =1.5.1-1" The problem has been fixed upstream [0] in version 1.5.1. Workaround ========= None. Description ========== Konversation's Blowfish ECB encryption support assumes incoming blocks to be the expected 12 bytes. The lack of a sanity-check for the actual size can cause a denial of service and an information leak to the local user. Impact ===== When using Blowfish ECB encryption with another party (an IRC channel or user), sending malformed blocks to konversation can result in a crash or an information leak up to 11 bytes to the local user, due to an out-of-bounds read on a heap-allocated array. References ========= [0] https://github.com/quassel/quassel/commit/8b5ecd https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8483 https://bugs.archlinux.org/task/42698 https://kde.org/info/security/advisory-20141104-1.txt . Debian Security Bulletin DSA-2023-370 details a minor risk of service disruption in gnome-shell versions before 3.36.9.. Arch Linux Denial Service, Konversation Security, Low Severity Advisory. . Severity: Low. LinuxSecurity.com Team
It was discovered that Konversation, an IRC client for KDE, could by crashed when receiving malformed messages using FiSH encryption. For the stable distribution (wheezy), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3068-1
Get the latest Linux and open source security news straight to your inbox.