8037 Recommended update for quassel moderate openSUSE Leap 42.3 Update This update for quassel fixes the following issues: Security fixes (boo#1090495): - CVE-2018-1000178: A heap metadata corruption in qdatastream could have been exploited to launch an unauthenticated remote code execution - CVE-2018-1000179: A remote attacker could have caused a Denial of Service attack by initiating login attempts before the core got initialized The following tracked packaging change is included: - boo#1069468: no longer use /var/adm/fillup-templates This update also includes various small bug fixes in the upstream 0.12.4 release. quassel-0.12.5-5.3.1.src.rpm quassel-base-0.12.5-5.3.1.x86_64.rpm quassel-client-0.12.5-5.3.1.x86_64.rpm quassel-client-debuginfo-0.12.5-5.3.1.x86_64.rpm quassel-client-qt5-0.12.5-5.3.1.x86_64.rpm quassel-client-qt5-debuginfo-0.12.5-5.3.1.x86_64.rpm quassel-core-0.12.5-5.3.1.x86_64.rpm quassel-core-debuginfo-0.12.5-5.3.1.x86_64.rpm quassel-debugsource-0.12.5-5.3.1.x86_64.rpm quassel-mono-0.12.5-5.3.1.x86_64.rpm quassel-mono-debuginfo-0.12.5-5.3.1.x86_64.rpm