CVE-2016-7045: Buffer Overflow
Published Sep 27, 2016
·Updated
The formatsendtogui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string.
Affected Software
3 affected components
Irssi irssi<=0.8.19
Debian Debian Linux=8.0
Canonical Ubuntu Linux=16.04
Remediation
Patch Available
Event History
Sep 27, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7045?
CVE-2016-7045 has a high severity rating due to its potential to cause a denial of service through heap corruption.
2
How do I fix CVE-2016-7045?
To fix CVE-2016-7045, update Irssi to version 0.8.20 or later, and ensure your system packages are up-to-date.
3
Which versions of Irssi are affected by CVE-2016-7045?
CVE-2016-7045 affects Irssi versions prior to 0.8.20.
4
What types of systems are impacted by CVE-2016-7045?
CVE-2016-7045 impacts Debian Linux 8.0 and Ubuntu Linux 16.04 along with any versions of Irssi prior to 0.8.20.
5
What is the attack vector for CVE-2016-7045?
The attack vector for CVE-2016-7045 involves sending specially crafted strings that lead to a crash of the Irssi application.