Bug#836706: certificate spoofing via crafted SASL messages

2016-09-06 Thread Guillaume Delacour
Please see attached the debdiff. Also, please note that i can't upload myself to security-master as i'm not a DD nor DM. Le 06/09/2016 à 00:02, Guillaume Delacour a écrit : > > > Le 05/09/2016 à 22:41, James Lu a écrit : >> Hi, > > Hi, > >> >> Just to narrow things down a bit, the relevant

Bug#836706: certificate spoofing via crafted SASL messages

2016-09-05 Thread Guillaume Delacour
Le 05/09/2016 à 22:41, James Lu a écrit : > Hi, Hi, > > Just to narrow things down a bit, the relevant fix for InspIRCd 2.0 is > this commit > https://github.com/inspircd/inspircd/commit/74fafb7f11b06747f69f182ad5e3769b665eea7a Yes, i've talked to upstream a few hours ago to include this

Bug#836706: certificate spoofing via crafted SASL messages

2016-09-05 Thread James Lu
Hi, Just to narrow things down a bit, the relevant fix for InspIRCd 2.0 is this commit https://github.com/inspircd/inspircd/commit/74fafb7f11b06747f69f182ad5e3769b665eea7a Best, James signature.asc Description: OpenPGP digital signature

Bug#836706: certificate spoofing via crafted SASL messages

2016-09-04 Thread Antoine Beaupré
Source: inspircd Version: 2.0.5-1+deb7u2 Severity: critical Tags: security inspircd published 2.0.23 that fixes an issue with SASL authentication. The details are here: http://www.inspircd.org/2016/09/03/v2023-released.html All versions are affected. Upstream hasn't requested a CVE yet. I will