Upstream information
Description
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
National Vulnerability Database | |
---|---|
Base Score | 5 |
Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Partial |
National Vulnerability Database | |
---|---|
Base Score | 7.5 |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | High |
CVSSv3 Version | 3 |
SUSE Security Advisories:
- openSUSE-SU-2017:1505-1, published Thu, 8 Jun 2017 18:09:45 +0200 (CEST)
- openSUSE-SU-2017:1515-1, published Thu, 8 Jun 2017 18:25:36 +0200 (CEST)
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Package Hub 12 |
| Patchnames: openSUSE-2017-668 |
openSUSE Tumbleweed |
| Patchnames: openSUSE Tumbleweed GA irssi-1.2.3-2.4 |
SUSE Timeline for this CVE
CVE page created: Wed Jun 7 05:26:43 2017CVE page last modified: Wed Oct 26 20:40:06 2022