[arch-security] [ASA-201711-19] konversation: denial of service
Morten Linderud
foxboron at archlinux.org
Tue Nov 14 15:13:49 UTC 2017
Arch Linux Security Advisory ASA-201711-19
==========================================
Severity: Medium
Date : 2017-11-12
CVE-ID : CVE-2017-15923
Package : konversation
Type : denial of service
Remote : Yes
Link : https://security.archlinux.org/AVG-489
Summary
=======
The package konversation before version 1.7.3-1 is vulnerable to denial
of service.
Resolution
==========
Upgrade to 1.7.3-1.
# pacman -Syu "konversation>=1.7.3-1"
The problem has been fixed upstream in version 1.7.3.
Workaround
==========
Go to Interface -> Colors in the Configure Konversation dialog and
uncheck Allow Colored Text in IRC Messages (near the bottom)
Description
===========
A denial of service vulnerability has been discovered in Konversation
before 1.7.3 when handling colors in IRC messages. Any malicious user
connected to the same IRC network could send a carefully crafted
message that would crash the Konversation user client.
Impact
======
A remote attacker is able to craft messages that can result in the
client crashing.
References
==========
https://www.kde.org/info/security/advisory-20171112-1.txt
https://cgit.kde.org/konversation.git/commit/?h=1.7&id=34cc9556c1a089fac6b674d3bd6f2248e9512902
https://security.archlinux.org/CVE-2017-15923
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.archlinux.org/pipermail/arch-security/attachments/20171114/c09b7456/attachment.asc>
More information about the arch-security
mailing list