<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>23317</bug_id>
          
          <creation_ts>2010-04-11 00:26:34 +0400</creation_ts>
          <short_desc>Irssi 0.8.15 Released</short_desc>
          <delta_ts>2010-04-19 13:43:30 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>irssi</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://irssi.org/news</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sir Raorn">raorn</reporter>
          <assigned_to name="Vladimir Lettiev">crux</assigned_to>
          <cc>crux</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>108517</commentid>
    <comment_count>0</comment_count>
    <who name="Sir Raorn">raorn</who>
    <bug_when>2010-04-11 00:26:34 +0400</bug_when>
    <thetext>The Irssi team is pleased to announce the 0.8.15 release of Irssi. It has been quite some time since our last release and there has been various feature enhancements and bugfixes added since then.

This release fixes two security issues: The first being that Irssi didn&apos;t check hostname on SSL connections and the other being a hard to exploit remote crash bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>108728</commentid>
    <comment_count>1</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-04-19 13:43:30 +0400</bug_when>
    <thetext>irssi-0.8.15-alt1 -&gt; sisyphus:

* Mon Apr 19 2010 Vladimir V. Kamarzin &lt;vvk@altlinux&gt; 0.8.15-alt1

- 0.8.15 (Closes: #23317). Security fixes:
  + CVE-2010-1155 (poor verification the hostname of the server when
    using SSL connections)
  + CVE-2010-1156 (A NULL-pointer dereference error in
    src/core/nicklist.c can be exploited to cause a crash)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>