cbcvebase.

Debian Irssi vulnerabilities

34 known vulnerabilities affecting debian/irssi.

Total CVEs
34
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM2LOW8

Vulnerabilities

Page 1 of 2
CVE-2009-1959P4LOWCVSS 5.0PoCfixed in irssi 0.8.13-2 (bookworm)2009
CVE-2009-1959 [MEDIUM] CVE-2009-1959: irssi - Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in i... Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow. Scope: local bookworm: resolved (fixed in 0.8.13-2) bullseye: resolved (fixed in 0.8.13-2) forky: resolved (fixed in
debian
CVE-2019-13045P3LOWCVSS 8.1fixed in irssi 1.2.1-1 (bookworm)2019
CVE-2019-13045 [HIGH] CVE-2019-13045: irssi - Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is ena... Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server. Scope: local bookworm: resolved (fixed in 1.2.1-1) bullseye: resolved (fixed in 1.2.1-1) forky: resolved (fixed in 1.2.1-1) sid: resolved (fixed in 1.2.1-1) trixie: resolved (fixed in 1.2.1-1)
debian
CVE-2017-10966P3LOWCVSS 9.8fixed in irssi 1.0.4-1 (bookworm)2017
CVE-2017-10966 [CRITICAL] CVE-2017-10966: irssi - An issue was discovered in Irssi before 1.0.4. While updating the internal nick ... An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table. Scope: local bookworm: resolved (fixed in 1.0.4-1) bullseye: resolved (fixed in 1.0.4-1) forky: resolved
debian
CVE-2018-7054P3CRITICALCVSS 9.8fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-7054 [CRITICAL] CVE-2018-7054: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a... An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.
debian
CVE-2017-7191P3CRITICALCVSS 9.8fixed in irssi 1.0.2-1 (bookworm)2017
CVE-2017-7191 [CRITICAL] CVE-2017-7191: irssi - The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a den... The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.0.2-1) bullseye: resolved (fixed in 1.0.2-1) forky: resolved (fixed in 1.0.2-1) sid: resolved (fixed in 1.0.2-1) trixie: resolved (fixed in 1.0.2-1)
debian
CVE-2018-5208P3CRITICALCVSS 9.8fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-5208 [CRITICAL] CVE-2018-5208: irssi - In Irssi before 1.0.6, a calculation error in the completion code could cause a ... In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2019-15717P3CRITICALCVSS 9.8fixed in irssi 1.2.2-1 (bookworm)2019
CVE-2019-15717 [CRITICAL] CVE-2019-15717: irssi - Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double C... Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP. Scope: local bookworm: resolved (fixed in 1.2.2-1) bullseye: resolved (fixed in 1.2.2-1) forky: resolved (fixed in 1.2.2-1) sid: resolved (fixed in 1.2.2-1) trixie: resolved (fixed in 1.2.2-1)
debian
CVE-2017-9469P3HIGHCVSS 7.5fixed in irssi 1.0.3-1 (bookworm)2017
CVE-2017-9469 [HIGH] CVE-2017-9469: irssi - In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it t... In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash. Scope: local bookworm: resolved (fixed in 1.0.3-1) bullseye: resolved (fixed in 1.0.3-1) forky: resolved (fixed in 1.0.3-1) sid: resolved (fixed in 1.0.3-1) trixie:
debian
CVE-2018-5205P3HIGHCVSS 7.5fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-5205 [HIGH] CVE-2018-5205: irssi - When using incomplete escape codes, Irssi before 1.0.6 may access data beyond th... When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2018-5207P3HIGHCVSS 7.5fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-5207 [HIGH] CVE-2018-5207: irssi - When using an incomplete variable argument, Irssi before 1.0.6 may access data b... When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2019-5882P3CRITICALCVSS 9.8fixed in irssi 1.1.2-1 (bookworm)2019
CVE-2019-5882 [CRITICAL] CVE-2019-5882: irssi - Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from... Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer. Scope: local bookworm: resolved (fixed in 1.1.2-1) bullseye: resolved (fixed in 1.1.2-1) forky: resolved (fixed in 1.1.2-1) sid: resolved (fixed in 1.1.2-1) trixie: resolved (fixed in 1.1.2-1)
debian
CVE-2018-7053P3CRITICALCVSS 9.8fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-7053 [CRITICAL] CVE-2018-7053: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a... An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2017-10965P3LOWCVSS 9.8fixed in irssi 1.0.4-1 (bookworm)2017
CVE-2017-10965 [CRITICAL] CVE-2017-10965: irssi - An issue was discovered in Irssi before 1.0.4. When receiving messages with inva... An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer. Scope: local bookworm: resolved (fixed in 1.0.4-1) bullseye: resolved (fixed in 1.0.4-1) forky: resolved (fixed in 1.0.4-1) sid: resolved (fixed in 1.0.4-1) trixie: resolved (fixed in 1.0.4-1)
debian
CVE-2018-7051P3HIGHCVSS 7.5fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-7051 [HIGH] CVE-2018-7051: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain ni... An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme strings. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2018-5206P3CRITICALCVSS 9.8fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-5206 [CRITICAL] CVE-2018-5206: irssi - When the channel topic is set without specifying a sender, Irssi before 1.0.6 ma... When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2017-5193P3HIGHCVSS 7.5fixed in irssi 0.8.21-1 (bookworm)2017
CVE-2017-5193 [HIGH] CVE-2017-5193: irssi - The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a d... The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a nick. Scope: local bookworm: resolved (fixed in 0.8.21-1) bullseye: resolved (fixed in 0.8.21-1) forky: resolved (fixed in 0.8.21-1) sid: resolved (fixed in 0.8.21-1) trixie: resolved (fixed in 0.8.21-1)
debian
CVE-2017-5195P3HIGHCVSS 7.5fixed in irssi 0.8.21-1 (bookworm)2017
CVE-2017-5195 [HIGH] CVE-2017-5195: irssi - Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service ... Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code. Scope: local bookworm: resolved (fixed in 0.8.21-1) bullseye: resolved (fixed in 0.8.21-1) forky: resolved (fixed in 0.8.21-1) sid: resolved (fixed in 0.8.21-1) trixie: resolved (fixed in 0.8.21-1)
debian
CVE-2017-15228P3HIGHCVSS 7.5fixed in irssi 1.0.5-1 (bookworm)2017
CVE-2017-15228 [HIGH] CVE-2017-15228: irssi - Irssi before 1.0.5, when installing themes with unterminated colour formatting s... Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string. Scope: local bookworm: resolved (fixed in 1.0.5-1) bullseye: resolved (fixed in 1.0.5-1) forky: resolved (fixed in 1.0.5-1) sid: resolved (fixed in 1.0.5-1) trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2017-5194P3HIGHCVSS 7.5fixed in irssi 0.8.21-1 (bookworm)2017
CVE-2017-5194 [HIGH] CVE-2017-5194: irssi - Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to c... Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message. Scope: local bookworm: resolved (fixed in 0.8.21-1) bullseye: resolved (fixed in 0.8.21-1) forky: resolved (fixed in 0.8.21-1) sid: resolved (fixed in 0.8.21-1) trixie: resolved (fixed in 0.8.21-1)
debian
CVE-2016-7045P3HIGHCVSS 7.5fixed in irssi 0.8.20-1 (bookworm)2016
CVE-2016-7045 [HIGH] CVE-2016-7045: irssi - The format_send_to_gui function in the format parsing code in Irssi before 0.8.2... The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string. Scope: local bookworm: resolved (fixed in 0.8.20-1) bullseye: resolved (fixed in 0.8.20-1) forky: resolved (fixed in 0.8.20-1) sid: resolved (fixed in 0.8.20-1) tr
debian
Debian Irssi vulnerabilities | cvebase