Buffer over-read in Irssi - CVE-2018-5205
Published: April 3, 2018
Vulnerability identifier: #VU11471
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5205
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to data access beyond the end of the string when using incomplete escape codes. A remote attacker can trigger buffer over-read and gain access to potentially sensitive information.
The weakness exists due to data access beyond the end of the string when using incomplete escape codes. A remote attacker can trigger buffer over-read and gain access to potentially sensitive information.
Affected software
Irssi
Arch Linux
Debian Linux
Slackware Linux
Ubuntu
Fedora
irssi (Alpine package)
irssi
Arch Linux
Debian Linux
Slackware Linux
Ubuntu
Fedora
irssi (Alpine package)
irssi
How to mitigate CVE-2018-5205
Update to version 1.0.6.
irssi (Alpine package) - update to 1.0.6-r0
irssi - addressed in versions 1.0.6-1.fc26, 1.0.6-1.fc27
irssi - addressed in versions 1.0.6-1.fc26, 1.0.6-1.fc27