Out-of-bounds read in Irssi - CVE-2017-5196
Published: March 3, 2017 / Updated: July 18, 2020
Vulnerability identifier: #VU31441
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5196
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are not UTF8.
Affected software
Irssi
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
irssi (Alpine package)
irssi
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
irssi (Alpine package)
irssi
How to mitigate CVE-2017-5196
Install update from vendor's website.
Irssi - update to 0.8.21
irssi (Alpine package) - update to 0.8.21-r0
irssi - addressed in versions 0.8.21-1.fc24, 0.8.21-1.fc25
irssi (Alpine package) - update to 0.8.21-r0
irssi - addressed in versions 0.8.21-1.fc24, 0.8.21-1.fc25