Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825). Also, the default IRC server has been changed from Freenode to Libera Chat, as . MGASA-2021-0382 - Updated quassel packages fix a security vulnerability Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0382.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-34825 Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825). Also, the default IRC server has been changed from Freenode to Libera Chat, as upstream has moved their #quassel channel there. References: - https://bugs.mageia.org/show_bug.cgi?id=29193 - https://quassel-irc.org/node/136 - https://lists.fedoraproject.org/archives/list/
Quassel could be made to crash or run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4594-1 October 20, 2020 quassel vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Quassel could be made to crash or run programs if it received specially crafted network traffic. Software Description: - quassel: distributed IRC client - monolithic core+client Details: It was discovered that Quassel incorrectly handled Qdatastream protocol. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2018-1000178) It was discovered that Quassel incorrectly handled certain login requests. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2018-1000179) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: quassel 1:0.12.4-3ubuntu1.18.04.3 quassel-core 1:0.12.4-3ubuntu1.18.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4594-1 CVE-2018-1000178, CVE-2018-1000179 Package Information: https://launchpad.net/ubuntu/+source/quassel/1:0.12.4-3ubuntu1.18.04.3 . Ubuntu Security Notice USN-4595-1 highlights significant vulnerabilities in qemu that affect system reliability and overall safety.. Quassel Vulnerability, Ubuntu Security, Remote Code Exploit, Denial of Service, Software Update. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Quassel, the worst of which could allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201806-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Quassel: Multiple vulnerabilities Date: June 14, 2018 Bugs: #653834 ID: 201806-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Quassel, the worst of which could allow remote attackers to execute arbitrary code. Background ========= Quassel is a Qt4/KDE4 IRC client suppporting a remote daemon for 24/7 connectivity. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/quassel < 0.12.5 > = 0.12.5 Description ========== Multiple vulnerabilities have been discovered in Quassel. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could cause arbitrary code execution or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Quassel users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/quassel-0.12.5" References ========= [ 1 ] CVE-2018-1000178 https://nvd.nist.gov/vuln/detail/CVE-2018-1000178 [ 2 ] CVE-2018-1000179 https://nvd.nist.gov/vuln/detail/CVE-2018-1000179 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201806-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Updated to latest upstream release (#1571443, #1573318, #1573319).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-bd73ec6f3a 2018-05-11 01:48:15.641788 --------------------------------------------------------------------------------Name : quassel Product : Fedora 27 Version : 0.12.5 Release : 1.fc27 URL : https://quassel-irc.org/ Summary : A modern distributed IRC system Description : Quassel IRC is a modern, distributed IRC client, meaning that one (or multiple) client(s) can attach to and detach from a central core --much like the popular combination of screen and a text-based IRC client such as WeeChat, but graphical --------------------------------------------------------------------------------Update Information: Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------ChangeLog: * Mon Apr 30 2018 Ben Rosser - 0.12.5-1 - Updated to latest upstream release (#1571443, #1573318, #1573319). * Fri Feb 9 2018 Fedora Release Engineering - 0.12.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering - 0.12.4-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Thu Jul 27 2017 Fedora Release Engineering - 0.12.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1573318 - quassel: multiple vulnerabilities fixed in 0.12.5 https://bugzilla.redhat.com/show_bug.cgi?id=1573318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-bd73ec6f3a' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated to latest upstream release (#1571443, #1573318, #1573319).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-9617cb1088 2018-05-11 01:22:39.912107 --------------------------------------------------------------------------------Name : quassel Product : Fedora 28 Version : 0.12.5 Release : 1.fc28 URL : https://quassel-irc.org/ Summary : A modern distributed IRC system Description : Quassel IRC is a modern, distributed IRC client, meaning that one (or multiple) client(s) can attach to and detach from a central core --much like the popular combination of screen and a text-based IRC client such as WeeChat, but graphical --------------------------------------------------------------------------------Update Information: Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------ChangeLog: * Mon Apr 30 2018 Ben Rosser - 0.12.5-1 - Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------References: [ 1 ] Bug #1573318 - quassel: multiple vulnerabilities fixed in 0.12.5 https://bugzilla.redhat.com/show_bug.cgi?id=1573318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-9617cb1088' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated to latest upstream release (#1571443, #1573318, #1573319).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5e8de70380 2018-05-11 01:00:00.882738 --------------------------------------------------------------------------------Name : quassel Product : Fedora 26 Version : 0.12.5 Release : 1.fc26 URL : https://quassel-irc.org/ Summary : A modern distributed IRC system Description : Quassel IRC is a modern, distributed IRC client, meaning that one (or multiple) client(s) can attach to and detach from a central core --much like the popular combination of screen and a text-based IRC client such as WeeChat, but graphical --------------------------------------------------------------------------------Update Information: Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------ChangeLog: * Mon Apr 30 2018 Ben Rosser - 0.12.5-1 - Updated to latest upstream release (#1571443, #1573318, #1573319). * Fri Feb 9 2018 Fedora Release Engineering - 0.12.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering - 0.12.4-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Thu Jul 27 2017 Fedora Release Engineering - 0.12.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1573318 - quassel: multiple vulnerabilities fixed in 0.12.5 https://bugzilla.redhat.com/show_bug.cgi?id=1573318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-5e8de70380' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code. . Package : quassel Version : 0.8.0-1+deb7u4 CVE ID : CVE-2018-1000178 It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code. For Debian 7 "Wheezy", these problems have been fixed in version 0.8.0-1+deb7u4. We recommend that you upgrade your quassel packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Quassel IRC client has issued a critical security update to address remote code execution vulnerabilities impacting Debian 7 Wheezy. Users should update immediately. Quassel IRC, Remote Code Execution, Debian 7 Security Update. . Severity: Critical. LinuxSecurity.com Team
Two vulnerabilities were found in the Quassel IRC client, which could result in the execution of arbitrary code or denial of service. Note that you need to restart the 'quasselcore' service after upgrading . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4189-1
Get the latest Linux and open source security news straight to your inbox.