[arch-security] [ASA-201706-11] irssi: denial of service
rgacogne at archlinux.org
Mon Jun 12 13:40:02 UTC 2017
Arch Linux Security Advisory ASA-201706-11
Date : 2017-06-12
CVE-ID : CVE-2017-9468 CVE-2017-9469
Package : irssi
Type : denial of service
Remote : Yes
Link : https://security.archlinux.org/AVG-293
The package irssi before version 1.0.3-1 is vulnerable to denial of
Upgrade to 1.0.3-1.
# pacman -Syu "irssi>=1.0.3-1"
The problems have been fixed upstream in version 1.0.3.
- CVE-2017-9468 (denial of service)
In Irssi before 1.0.3, when receiving a DCC message without source
nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC
servers can cause a crash.
- CVE-2017-9469 (denial of service)
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC
files, it tries to find the terminating quote one byte before the
allocated memory. Thus, remote attackers might be able to cause a
A remote attacker can cause a denial of service by sending a crafted
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: OpenPGP digital signature
More information about the arch-security