This release fixes a remotely-exploitable crash in the Konversation
IRC client.
Details
Details
- Reviewers
tcberner rakuco - Commits
- rP454088: Update irc/konversation to latest upstream release.
Diff Detail
Diff Detail
- Repository
- rP FreeBSD ports repository
- Lint
Lint Not Applicable - Unit
Tests Not Applicable
Event Timeline
security/vuxml/vuln.xml | ||
---|---|---|
65 ↗ | (On Diff #35172) | # pkg audit -f ./vuln.xml konversation-1.7.2 0 problem(s) in the installed packages found. ohhh. that is wrong, isn't it :) you need the package name there, i.e konversation |
security/vuxml/vuln.xml | ||
---|---|---|
78 ↗ | (On Diff #35172) | You could keep the url field additionally too. |
security/vuxml/vuln.xml | ||
---|---|---|
79 ↗ | (On Diff #35175) | you could also add a secondary <url>https://www.kde.org/info/security/advisory-20171112-1.txt</url> |
Comment Actions
After that, on to the committing stage -- two separate commits:
- security/vuxml
- commit message somthing ala Document new vulnerabilities in irc/konversation < 1.7.3
- irc/konversation
- Normal commit message
- This time, additionally use the field MFH: 2017Q4