Your message dated Fri, 19 Jun 2009 09:47:11 +0000
with message-id <[email protected]>
and subject line Bug#531357: fixed in irssi 0.8.13-2
has caused the Debian Bug report #531357,
regarding irssi WALLOPS heap off-by-one
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
531357: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=531357
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: irssi
Version: 1.3-18
Severity: grave

A remotely exploitable off-by-one was found in irssi 0.8.13. It's exloitable from a server only.
See http://bugs.irssi.org/index.php?do=details&task_id=662 and
http://xorl.wordpress.com/2009/05/28/irssi-event_wallops-off-by-one-readwrite/

Best regards,

Craig



--- End Message ---
--- Begin Message ---
Source: irssi
Source-Version: 0.8.13-2

We believe that the bug you reported is fixed in the latest version of
irssi, which is due to be installed in the Debian FTP archive:

irssi-dev_0.8.13-2_powerpc.deb
  to pool/main/i/irssi/irssi-dev_0.8.13-2_powerpc.deb
irssi_0.8.13-2.diff.gz
  to pool/main/i/irssi/irssi_0.8.13-2.diff.gz
irssi_0.8.13-2.dsc
  to pool/main/i/irssi/irssi_0.8.13-2.dsc
irssi_0.8.13-2_powerpc.deb
  to pool/main/i/irssi/irssi_0.8.13-2_powerpc.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Gerfried Fuchs <[email protected]> (supplier of updated irssi package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 16 Jun 2009 11:03:06 +0200
Source: irssi
Binary: irssi irssi-dev
Architecture: source powerpc
Version: 0.8.13-2
Distribution: unstable
Urgency: medium
Maintainer: David Pashley <[email protected]>
Changed-By: Gerfried Fuchs <[email protected]>
Description: 
 irssi      - terminal based IRC client
 irssi-dev  - terminal based IRC client - development files
Closes: 531357
Changes: 
 irssi (0.8.13-2) unstable; urgency=medium
 .
   * New patch:
     - wallops-fix: Fix CVE-2009-1959 off-by-one in event_wallops
       (closes: #531357)
Checksums-Sha1: 
 4fc61abc6f7edaf15777d14b8c6318f2aa6276a6 1270 irssi_0.8.13-2.dsc
 c2971eacac7a638caa9fa2a2aa588dca533ed331 16265 irssi_0.8.13-2.diff.gz
 63860c90350cb83803f692738ed13c574c2a33e5 1158742 irssi_0.8.13-2_powerpc.deb
 c6972e80bfdec1e09e23a606ac94ef232cd43d4f 290440 irssi-dev_0.8.13-2_powerpc.deb
Checksums-Sha256: 
 6f32cb9edf16f1f773ec6c1e12237331058c3e7f83f55cc5d12fd710f95933d8 1270 
irssi_0.8.13-2.dsc
 447e048904c07c4b312c6f6cfc763e3d67979f9dcfdc6148dff20fb5c176b1f2 16265 
irssi_0.8.13-2.diff.gz
 82439a80a04e4da8b80e43f61bc7b0f9953e2908d9ed0fa49a64a74bef077802 1158742 
irssi_0.8.13-2_powerpc.deb
 f444177e6e529a2d2588d7608d18cd7b22439f3a14eec88670954ce03a2cd950 290440 
irssi-dev_0.8.13-2_powerpc.deb
Files: 
 43c5d6dde2e9c4c3b60b43b442f4e7a1 1270 net optional irssi_0.8.13-2.dsc
 4657996a0b49222735415d0867ac3f6f 16265 net optional irssi_0.8.13-2.diff.gz
 1252dfa956028e6a7598cee6ca4e0bfe 1158742 net optional 
irssi_0.8.13-2_powerpc.deb
 ba5163f8ab6db984577381f3472fd26b 290440 net optional 
irssi-dev_0.8.13-2_powerpc.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAko7XNwACgkQELuA/Ba9d8aHgACcDshpFfDfxdNUBTbf9yTE16gA
h8UAoNhK5XUYl6c61C9Shvp632y8vJuG
=dBmI
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to