-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3063-1 security@debian.org http://www.debian.org/security/ Luciano Bello November 02, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : quassel CVE ID : CVE-2014-8483 Debian Bug : 766962 An out-of-bounds read vulnerability was discovered in Quassel-core, one of the components of the distributed IRC client Quassel. An attacker can send a crafted message that crash to component causing a denial of services or disclosure of information from process memory. For the stable distribution (wheezy), this problem has been fixed in version 0.8.0-1+deb7u3. For the unstable distribution (sid), this problem has been fixed in version 0.10.0-2.1 (will be available soon). We recommend that you upgrade your quassel packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJUVqKrAAoJEG7C3vaP/jd0V54P/1VJfO+kai33curXU7BsJ//A zmXLmdqVgoVLwaSzUHS+f1YN2/hitme8CDuMFtM84HnoFwZqatMg28zwFnWxbv8Q QFmWVixvSVv01l3tkfhe+6mpZGrc+tLCFddLcCdJseJ7JUnzgmQPVupAJFbw2gTb Ge8BmrqFN0UWkyn5oCU500e3kL/dHpNLOA3U7scl4SsIqVReDSSpRqfE5cLuZw5w qmagxr2Xq3rW3vvlJ5+HTXtTEgZaDn1Ir6CTkslO9AuzRScW0AotNGgqWeUy+TJG ba+3dm4MJTtxcb+3XrPVI5cHAZBS/TkKmJWWurre84gdFPs2Hmegw+p0PGCrGHDM GpX9pK4CGSDi5kUsb3jMLIBNoKIK0lmJxMcW4RJckEmQtH948MUrCZn+i84WhgMa oSsP3Q2FgueMIyVvedr5sYeYYZPBdr2oJ+IuybhvEoSpAM9GO2Mqu2dcfqA7g3OS UkbiE/IyAVSCZu7D43P3JbE5/Fp64BfijqecHRPgH0XQc72vpCo4Vmv5XqcgL47W A2vCS+f37oBwfk5OCZzo0mTxFdjmCNQ/vAR6TUD53oqp/ymmEJNH+ubZjkvfcDq7 EQEuRrVJHncjfdBQhKQeu8IAYaEZxcVjS7oIvH3Ii58NXeqK709Q3+f8wawh01cV hAPDXr9QKOOUP5dh6eR8 =i7wv -----END PGP SIGNATURE-----