CVE-2017-9469
published 2017-06-07CVE-2017-9469: In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.08%
92.6th percentile
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | irssi | < irssi 1.0.3-1 (bookworm) | irssi 1.0.3-1 (bookworm) |
| irssi | irssi | <= 1.0.2 | — |
| irssi | irssi | >= 0 < 1.0.3-1 | 1.0.3-1 |
| irssi | irssi | >= 0 < 1.0.3-1 | 1.0.3-1 |
| irssi | irssi | >= 0 < 1.0.3-1 | 1.0.3-1 |
| irssi | irssi | >= 0 < 1.0.3-1 | 1.0.3-1 |
| irssi | irssi | >= 0 < 0.8.15-5ubuntu3.2 | 0.8.15-5ubuntu3.2 |
| irssi | irssi | >= 0 < 0.8.19-1ubuntu1.4 | 0.8.19-1ubuntu1.4 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Irssi vulnerabilities
vendor_ubuntu·2017-06-12·CVSS 7.5
CVE-2017-9468 [HIGH] Irssi vulnerabilities
Title: Irssi vulnerabilities
Summary: Irssi could be made to crash if it received specially crafted network
traffic.
It was discovered that Irssi incorrectly handled certain DCC messages. A
malicious IRC server could use this issue to cause Irssi to crash,
resulting in a denial of service. (CVE-2017-9468)
Joseph Bisch discovered that Irssi incorrectly handled receiving
incorrectly quoted DCC files. A remote attacker could possibly use this
issue to cause Irssi to crash, resulting in a denial of service.
(CVE-2017-9469)
Instructions: After a standard system update you need to restart Irssi to make all the
necessary changes.
Red Hat
irssi: Invalid read when receiving certain incorrectly quoted DCC files
vendor_redhat·2017-06-07·CVSS 7.5
CVE-2017-9469 [HIGH] CWE-129 irssi: Invalid read when receiving certain incorrectly quoted DCC files
irssi: Invalid read when receiving certain incorrectly quoted DCC files
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
An out-of-bound heap read was found in irssi's get_file_params_count() function, during the parsing of a DCC SEND request. An IRC client connected to the same IRC network as the target could send a specially crafted request that would force irssi to read 1 byte outside of an allocated string, which could, possibly, lead to an invalid memory read.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For addit
Debian
CVE-2017-9469: irssi - In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it t...
vendor_debian·2017·CVSS 7.5
CVE-2017-9469 [HIGH] CVE-2017-9469: irssi - In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it t...
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
Scope: local
bookworm: resolved (fixed in 1.0.3-1)
bullseye: resolved (fixed in 1.0.3-1)
forky: resolved (fixed in 1.0.3-1)
sid: resolved (fixed in 1.0.3-1)
trixie: resolved (fixed in 1.0.3-1)
GHSA
GHSA-4fcw-x547-92cj: In Irssi before 1
ghsa_unreviewed·2022-05-14
CVE-2017-9469 [HIGH] CWE-119 GHSA-4fcw-x547-92cj: In Irssi before 1
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
OSV
irssi vulnerabilities
osv·2017-06-12·CVSS 7.5
CVE-2017-9468 [HIGH] irssi vulnerabilities
irssi vulnerabilities
It was discovered that Irssi incorrectly handled certain DCC messages. A
malicious IRC server could use this issue to cause Irssi to crash,
resulting in a denial of service. (CVE-2017-9468)
Joseph Bisch discovered that Irssi incorrectly handled receiving
incorrectly quoted DCC files. A remote attacker could possibly use this
issue to cause Irssi to crash, resulting in a denial of service.
(CVE-2017-9469)
OSV
CVE-2017-9469: In Irssi before 1
osv·2017-06-07·CVSS 7.5
CVE-2017-9469 [HIGH] CVE-2017-9469: In Irssi before 1
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9468 CVE-2017-9469 irssi: various flaws [fedora-all]
bugzilla·2017-06-07·CVSS 7.5
CVE-2017-9468 [HIGH] CVE-2017-9468 CVE-2017-9469 irssi: various flaws [fedora-all]
CVE-2017-9468 CVE-2017-9469 irssi: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2017-9469 irssi: Invalid read when receiving certain incorrectly quoted DCC files
bugzilla·2017-06-07·CVSS 7.5
CVE-2017-9469 [HIGH] CVE-2017-9469 irssi: Invalid read when receiving certain incorrectly quoted DCC files
CVE-2017-9469 irssi: Invalid read when receiving certain incorrectly quoted DCC files
When receiving certain incorrectly quoted DCC files, Irssi would try to find the terminating quote one byte before the allocated memory. A remote attacker could possibly use this to crash irssi.
External References:
https://irssi.org/security/irssi_sa_2017_06.txt
Discussion:
Created irssi tracking bugs for this issue:
Affects: fedora-all [bug 1459458]
---
Lowering impact: the vulnerability allows an out of bound read 1 byte outside of the allocated memory. As shipped in RHEL, this will not cause an invalid memory access.
---
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additiona
http://openwall.com/lists/oss-security/2017/06/06/4http://www.debian.org/security/2017/dsa-3885http://www.securityfocus.com/bid/99043http://www.securitytracker.com/id/1038621https://irssi.org/security/irssi_sa_2017_06.txthttp://openwall.com/lists/oss-security/2017/06/06/4http://www.debian.org/security/2017/dsa-3885http://www.securityfocus.com/bid/99043http://www.securitytracker.com/id/1038621https://irssi.org/security/irssi_sa_2017_06.txt
2017-06-07
Published