CVE-2017-15228: High severity irssi vulnerability
Published Oct 22, 2017
·Updated
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
Affected Software
2 affected componentsFixes available
debian/irssi
1.2.0-2+deb10u11.2.3-11.4.3-21.4.5-1
Irssi irssi<=1.0.4
Remediation
Patch Available
Patch Available
Event History
Oct 22, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15228?
CVE-2017-15228 has a medium severity rating due to potential access to out-of-bounds data.
2
How do I fix CVE-2017-15228?
To fix CVE-2017-15228, update Irssi to version 1.0.5 or later.
3
What versions of Irssi are affected by CVE-2017-15228?
Irssi versions before 1.0.5 are affected by CVE-2017-15228.
4
Can CVE-2017-15228 lead to data leakage?
Yes, CVE-2017-15228 may lead to data leakage by accessing memory beyond allocated buffers.
5
Is CVE-2017-15228 a local or remote vulnerability?
CVE-2017-15228 is primarily a local vulnerability that could be exploited by a user with the ability to install themes.