Out-of-bounds read in Irssi - CVE-2017-15228

 

Out-of-bounds read in Irssi - CVE-2017-15228

Published: October 22, 2017 / Updated: July 28, 2020


Vulnerability identifier: #VU32047
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-15228
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Irssi
Software vendor:
Irssi.org

Description

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.


Remediation

Install update from vendor's website.

External links