CVE-2017-9469: Buffer Overflow
Published Jun 7, 2017
·Updated
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
Affected Software
3 affected components
Irssi irssi<=1.0.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Patch Available
Event History
Jun 7, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9469?
CVE-2017-9469 has a high severity rating due to the potential for remote attackers to cause application crashes.
2
How do I fix CVE-2017-9469?
To resolve CVE-2017-9469, update Irssi to version 1.0.3 or later.
3
Which versions of Irssi are affected by CVE-2017-9469?
Irssi versions prior to 1.0.3, specifically 1.0.2 and below, are impacted by CVE-2017-9469.
4
Can CVE-2017-9469 be exploited remotely?
Yes, CVE-2017-9469 can be exploited remotely by sending specially crafted DCC file transfers.
5
Is there a workaround for CVE-2017-9469?
Currently, the best course of action is to upgrade Irssi, as there are no known effective workarounds for CVE-2017-9469.