Out-of-bounds read in Irssi - CVE-2017-15228
Published: October 22, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32047
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15228
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
Affected software
Irssi
Arch Linux
Slackware Linux
irssi (Alpine package)
Arch Linux
Slackware Linux
irssi (Alpine package)
How to mitigate CVE-2017-15228
Install update from vendor's website.
Irssi - update to 1.0.5
irssi (Alpine package) - addressed in versions 1.0.5-r0, 1.0.6-r0
irssi (Alpine package) - addressed in versions 1.0.5-r0, 1.0.6-r0