Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-1959Off-by-one Error in Irssi

Severity
5.0MEDIUMNVD
EPSS
6.9%
top 8.56%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 8
Latest updateMay 2

Description

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/irssi< irssi 0.8.13-2 (bookworm)
Debianirssi/irssi< 0.8.13-2+3
NVDirssi/irssi0.8.13

🔴Vulnerability Details

2
GHSA
GHSA-2v73-9rwq-75qc: Off-by-one error in the event_wallops function in fe-common/irc/fe-events2022-05-02
OSV
CVE-2009-1959: Off-by-one error in the event_wallops function in fe-common/irc/fe-events2009-06-08

💥Exploits & PoCs

1
Exploit-DB
Irssi 0.8.13 - 'WALLOPS' Message Off-by-One Heap Memory Corruption2009-05-15

📋Vendor Advisories

4
Ubuntu
irssi vulnerability2009-07-13
Red Hat
gnutls: incorrect handling of V1 intermediate certificates2009-01-09
Debian
CVE-2009-1959: irssi - Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in i...2009
Red Hat
irssi: off-by-one error in the event_wallops

💬Community

2
Bugzilla
CVE-2009-5138 gnutls: incorrect handling of V1 intermediate certificates2014-02-24
Bugzilla
CVE-2009-1959 irssi: off-by-one error in the event_wallops2009-06-08
CVE-2009-1959 — Off-by-one Error in Debian Irssi | cvebase