First published: Wed Jun 07 2017(Updated: )
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Irssi Irssi | <=1.0.2 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9469 has a high severity rating due to the potential for remote attackers to cause application crashes.
To resolve CVE-2017-9469, update Irssi to version 1.0.3 or later.
Irssi versions prior to 1.0.3, specifically 1.0.2 and below, are impacted by CVE-2017-9469.
Yes, CVE-2017-9469 can be exploited remotely by sending specially crafted DCC file transfers.
Currently, the best course of action is to upgrade Irssi, as there are no known effective workarounds for CVE-2017-9469.