Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825). Also, the default IRC server has been changed from Freenode to Libera Chat, as . MGASA-2021-0382 - Updated quassel packages fix a security vulnerability Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0382.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-34825 Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825). Also, the default IRC server has been changed from Freenode to Libera Chat, as upstream has moved their #quassel channel there. References: - https://bugs.mageia.org/show_bug.cgi?id=29193 - https://quassel-irc.org/node/136 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.