<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for konversation</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2017:3099-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2017-11-25T19:57:15Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2017-11-25T19:57:15Z</InitialReleaseDate>
    <CurrentReleaseDate>2017-11-25T19:57:15Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for konversation</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for konversation fixes the following issues:

Security issue fixed:

- CVE-2017-15923: Fixed a crash in parsing IRC color formatting codes (boo#1068097).

Bug fixes:

- Update to version 1.7.4:
  * Fixed a bug causing the size of a custom chat text view font
    set via the configuration dialog to be ignored. A font size
    modification done via the Enlarge/Decrease Font Size actions
    is now applied on top of the configured size (or the system
    default font size, respectively).
- Update to 1.7.3:
  * Added a copy action to the context menu of nicknames in the
    chat text view.
  * Re-enabled channel mode buttons.
  * Reduced emission of Unicode directional control characters in
    the chat text view. Unnecessary control characters could
    sometimes cause problems with copying text from Konversation
    and pasting it into terminal applications, confusing them.
  * Fixed handling of nick and channel prefix characters
    potentially using the same set of symbols.
  * Removed redundant escaping of angle brackets in GECOS
    ('realname') field.
  * The nickname combobox will no longer change the nickname to
    the current value whenvever it loses focus.
  * Fixed color scheme handling in the treelist version on the tab
    bar, fixing an issue where the background and text color of
    the selected item would sometimes be the same, rendering the
    item unreadable.
  * Fixed handling of IRC URLs for channels starting with more
    than one #, addressing a percent-encoding problem with
    bookmarks of them.
  * Fixed custom chat text view font family reverting to system
    default font family upon using the increase/decrease font size
    actions.
  * Fixed chat text view font size adjusted via the
    increase/decrease font size actions reverting to configuration
    default when OK'ing the config dialog.
  * Fixed incorrect checkbox states in the Channel Invite dialog.
  * Fixed a crash in IRC v3 extended-join parsing.
  * Fixed a crash in parsing IRC color formatting codes.
  * Fixed a minor memory leak in the Join Channel dialog code.
  * Removed unnecessary nickname list debug message sent as
    warning.
- Trim description from redundant phrasing, and ensure neutrality.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-updates/2017-11/msg00081.html</URL>
      <Description>E-Mail link for openSUSE-SU-2017:3099-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.3">
      <Branch Type="Product Name" Name="openSUSE Leap 42.3">
        <FullProductName ProductID="openSUSE Leap 42.3">openSUSE Leap 42.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="konversation-1.7.4-3.1">
      <FullProductName ProductID="konversation-1.7.4-3.1">konversation-1.7.4-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="konversation-lang-1.7.4-3.1">
      <FullProductName ProductID="konversation-lang-1.7.4-3.1">konversation-lang-1.7.4-3.1</FullProductName>
    </Branch>
    <Relationship ProductReference="konversation-1.7.4-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:konversation-1.7.4-3.1">konversation-1.7.4-3.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="konversation-lang-1.7.4-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:konversation-lang-1.7.4-3.1">konversation-lang-1.7.4-3.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.</Note>
    </Notes>
    <CVE>CVE-2017-15923</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:konversation-1.7.4-3.1</ProductID>
        <ProductID>openSUSE Leap 42.3:konversation-lang-1.7.4-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-11/msg00081.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-15923.html</URL>
        <Description>CVE-2017-15923</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1068097</URL>
        <Description>SUSE Bug 1068097</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
