CVE-2017-5356: High severity Irssi irssi vulnerability
Published Mar 3, 2017
·Updated
Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).
Affected Software
2 affected components
Irssi irssi<0.8.21
Debian Debian Linux=7.0
Remediation
Patch Available
Event History
Mar 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5356?
CVE-2017-5356 is classified as a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2017-5356?
To mitigate CVE-2017-5356, users should upgrade to Irssi version 0.8.21 or later.
3
What software is affected by CVE-2017-5356?
CVE-2017-5356 affects Irssi versions prior to 0.8.21 and Debian Linux version 7.0.
4
What type of attack does CVE-2017-5356 facilitate?
CVE-2017-5356 allows attackers to cause a denial of service through an out-of-bounds read.
5
Is CVE-2017-5356 an exploit that can be triggered remotely?
Yes, CVE-2017-5356 can be exploited by remote attackers by sending specially crafted strings.