CVE-2009-1959: Medium severity Irssi irssi vulnerability
Published Jun 6, 2009
·Updated
Off-by-one error in the eventwallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.
Affected Software
1 affected component
Irssi irssi=0.8.13
Event History
Jun 6, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1959?
CVE-2009-1959 is classified as a medium severity vulnerability due to the potential for denial of service.
2
How do I fix CVE-2009-1959?
To fix CVE-2009-1959, upgrade to a patched version of Irssi that addresses the off-by-one error, avoiding version 0.8.13.
3
What software is affected by CVE-2009-1959?
CVE-2009-1959 specifically affects Irssi version 0.8.13.
4
What type of vulnerability is CVE-2009-1959?
CVE-2009-1959 is an off-by-one error that results in a buffer under-read and underflow.
5
What can an attacker do with CVE-2009-1959?
An attacker can exploit CVE-2009-1959 to crash the Irssi client by sending an empty command.