First published: Wed Jan 10 2018(Updated: )
Joseph Bisch discovered that Irssi incorrectly handled incomplete escape codes. If a user were tricked into using malformed commands or opening malformed files, an attacker could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5205) Joseph Bisch discovered that Irssi incorrectly handled settings the channel topic without specifying a sender. A malicious IRC server could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5206) Joseph Bisch discovered that Irssi incorrectly handled incomplete variable arguments. If a user were tricked into using malformed commands or opening malformed files, an attacker could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5207) Joseph Bisch discovered that Irssi incorrectly handled completing certain strings. An attacker could use this issue to cause Irssi to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-5208)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/irssi | <1.0.4-1ubuntu2.2 | 1.0.4-1ubuntu2.2 |
Ubuntu Linux | =17.10 | |
All of | ||
ubuntu/irssi | <0.8.20-2ubuntu2.3 | 0.8.20-2ubuntu2.3 |
Ubuntu Linux | =17.04 | |
All of | ||
ubuntu/irssi | <0.8.19-1ubuntu1.6 | 0.8.19-1ubuntu1.6 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/irssi | <0.8.15-5ubuntu3.4 | 0.8.15-5ubuntu3.4 |
Ubuntu Linux | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-3527-1 is categorized as a denial of service vulnerability.
To fix USN-3527-1, upgrade the Irssi package to the version provided in the security notice.
USN-3527-1 affects Irssi versions before 1.0.4-1ubuntu2.2, 0.8.20-2ubuntu2.3, 0.8.19-1ubuntu1.6, and 0.8.15-5ubuntu3.4 on specified Ubuntu releases.
The vulnerability in USN-3527-1 was discovered by Joseph Bisch.
If you are affected by USN-3527-1, an attacker could potentially cause the Irssi application to crash.