CVE-2018-5205: High severity irssi vulnerability
Published Jan 6, 2018
·Updated
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
Affected Software
11 affected componentsFixes available
ubuntu/irssi<1.0.4-1ubuntu2.2
1.0.4-1ubuntu2.2
ubuntu/irssi<0.8.15-5ubuntu3.4
0.8.15-5ubuntu3.4
ubuntu/irssi<0.8.19-1ubuntu1.6
0.8.19-1ubuntu1.6
ubuntu/irssi<0.8.20-2ubuntu2.3
0.8.20-2ubuntu2.3
debian/irssi
1.2.3-11.4.3-21.4.5-1
Irssi irssi<1.0.6
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.04
Canonical Ubuntu Linux=17.10
Remediation
Patch Available
Event History
Jan 6, 2018
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Aug 5, 2024
Data Sourced
via Launchpad·05:39 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5205?
CVE-2018-5205 has been assessed as having moderate severity due to potential memory corruption issues.
2
How do I fix CVE-2018-5205?
To fix CVE-2018-5205, update Irssi to version 1.0.6 or later.
3
Which versions of Irssi are affected by CVE-2018-5205?
Irssi versions prior to 1.0.6 are affected by CVE-2018-5205.
4
Is CVE-2018-5205 present in Ubuntu distributions?
Yes, CVE-2018-5205 is present in various affected Ubuntu distributions prior to the patched versions.
5
What types of systems are vulnerable to CVE-2018-5205?
CVE-2018-5205 primarily affects systems running outdated versions of Irssi on Ubuntu and Debian.