USN-3527-1: Irssi vulnerabilities
Joseph Bisch discovered that Irssi incorrectly handled incomplete escape codes. If a user were tricked into using malformed commands or opening malformed files, an attacker could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5205) Joseph Bisch discovered that Irssi incorrectly handled settings the channel topic without specifying a sender. A malicious IRC server could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5206) Joseph Bisch discovered that Irssi incorrectly handled incomplete variable arguments. If a user were tricked into using malformed commands or opening malformed files, an attacker could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5207) Joseph Bisch discovered that Irssi incorrectly handled completing certain strings. An attacker could use this issue to cause Irssi to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-5208)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-3527-1?
The severity of USN-3527-1 is categorized as a denial of service vulnerability.
How do I fix USN-3527-1?
To fix USN-3527-1, upgrade the Irssi package to the version provided in the security notice.
Which versions of software are affected by USN-3527-1?
USN-3527-1 affects Irssi versions before 1.0.4-1ubuntu2.2, 0.8.20-2ubuntu2.3, 0.8.19-1ubuntu1.6, and 0.8.15-5ubuntu3.4 on specified Ubuntu releases.
Who discovered the vulnerability in USN-3527-1?
The vulnerability in USN-3527-1 was discovered by Joseph Bisch.
What can happen if I am affected by USN-3527-1?
If you are affected by USN-3527-1, an attacker could potentially cause the Irssi application to crash.