weechat security update

2017-09-24 Thread Daniel Jakots
Hi, Weechat 1.9.1 was released to fix CVE-2017-14727: Date/time conversion specifiers are expanded after replacing buffer local variables in name of log files. In some cases, this can lead to an error in function strftime and a crash caused by the use of an uninitialized buffer. Patch: https://gi

Re: weechat security update

2017-09-25 Thread Jeremie Courreges-Anglas
On Sun, Sep 24 2017, Daniel Jakots wrote: > Hi, > > Weechat 1.9.1 was released to fix CVE-2017-14727: > Date/time conversion specifiers are expanded after replacing buffer > local variables in name of log files. In some cases, this can lead to > an error in function strftime and a crash caused by