MGASA-2021-0382
Dashboard / Vulnerabilities / MGASA-2021-0382
Summary: Updated quassel packages fix a security vulnerability
Details: Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825). Also, the default IRC server has been changed from Freenode to Libera Chat, as upstream has moved their #quassel channel there.
References: https://advisories.mageia.org/MGASA-2021-0382.html, https://bugs.mageia.org/show_bug.cgi?id=29193, https://quassel-irc.org/node/136, https://lists.fedoraproject.org/archives/list/[email protected]/thread/7ZFWRN5P2WG23MWMVAEVV3YBHGFJHDSW/
Affected packages
Package
Name: quassel
Purl: pkg:rpm/mageia/quassel?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
