Out-of-bounds read in Irssi - CVE-2017-15228

 

Out-of-bounds read in Irssi - CVE-2017-15228

Published: October 22, 2017 / Updated: July 28, 2020


Vulnerability identifier: #VU32047
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15228
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.


Affected software

Irssi
Arch Linux
Slackware Linux
irssi (Alpine package)

How to mitigate CVE-2017-15228

Install update from vendor's website.

Irssi - update to 1.0.5
irssi (Alpine package) - addressed in versions 1.0.5-r0, 1.0.6-r0

External References

Related Security Bulletins