Debian Irssi vulnerabilities
34 known vulnerabilities affecting debian/irssi.
Total CVEs
34
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM2LOW8
Vulnerabilities
Page 2 of 2
CVE-2016-7044P3HIGHCVSS 7.5fixed in irssi 0.8.20-1 (bookworm)2016
CVE-2016-7044 [HIGH] CVE-2016-7044: irssi - The unformat_24bit_color function in the format parsing code in Irssi before 0.8...
The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomplete 24bit color code.
Scope: local
bookworm: resolved (fixed in 0.8.20-1)
bullseye: resolved (fixed in 0.8.20-1)
forky: resolved (fixed in 0.8.20-1)
sid:
debian
CVE-2017-15227P3HIGHCVSS 7.5fixed in irssi 1.0.5-1 (bookworm)2017
CVE-2017-15227 [HIGH] CVE-2017-15227: irssi - Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrect...
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
bullseye: resolved (fixed in 1.0.5-1)
forky: resolved (fixed in 1.0.5-1)
sid: resolved (fixed in 1.0.5-1)
tr
debian
CVE-2017-5196P3HIGHCVSS 7.5fixed in irssi 0.8.21-1 (bookworm)2017
CVE-2017-5196 [HIGH] CVE-2017-5196: irssi - Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service ...
Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are not UTF8.
Scope: local
bookworm: resolved (fixed in 0.8.21-1)
bullseye: resolved (fixed in 0.8.21-1)
forky: resolved (fixed in 0.8.21-1)
sid: resolved (fixed in 0.8.21-1)
trixie: resolved (fixed in 0.8.21-1)
debian
CVE-2017-5356P3LOWCVSS 7.5fixed in irssi 0.8.21-1 (bookworm)2017
CVE-2017-5356 [HIGH] CVE-2017-5356: irssi - Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of...
Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).
Scope: local
bookworm: resolved (fixed in 0.8.21-1)
bullseye: resolved (fixed in 0.8.21-1)
forky: resolved (fixed in 0.8.21-1)
sid: resolved (fixed in 0.8.21-1)
trixie: resolved (fixed i
debian
CVE-2017-9468P3HIGHCVSS 7.5fixed in irssi 1.0.3-1 (bookworm)2017
CVE-2017-9468 [HIGH] CVE-2017-9468: irssi - In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it...
In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.
Scope: local
bookworm: resolved (fixed in 1.0.3-1)
bullseye: resolved (fixed in 1.0.3-1)
forky: resolved (fixed in 1.0.3-1)
sid: resolved (fixed in 1.0.3-1)
trixie: resolved (fixed in 1.0.3-1)
debian
CVE-2017-15723P4HIGHCVSS 7.5fixed in irssi 1.0.5-1 (bookworm)2017
CVE-2017-15723 [HIGH] CVE-2017-15723: irssi - In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer de...
In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
bullseye: resolved (fixed in 1.0.5-1)
forky: resolved (fixed in 1.0.5-1)
sid: resolved (fixed in 1.0.5-1)
trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2017-15721P4HIGHCVSS 7.5fixed in irssi 1.0.5-1 (bookworm)2017
CVE-2017-15721 [HIGH] CVE-2017-15721: irssi - In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cau...
In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
bullseye: resolved (fixed in 1.0.5-1)
forky: resolved (fixed in 1.0.5-1)
sid: resolved (fixed in 1.0.5-1)
trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2018-7050P4HIGHCVSS 7.5fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-7050 [HIGH] CVE-2018-7050: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL poi...
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2018-7052P4HIGHCVSS 7.5fixed in irssi 1.0.7-1 (bookworm)2018
CVE-2018-7052 [HIGH] CVE-2018-7052: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the n...
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL pointer dereference would occur.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (fixed in 1.0.7-1
debian
CVE-2010-1155P4LOWCVSS 6.8fixed in irssi 0.8.15-1 (bookworm)2010
CVE-2010-1155 [MEDIUM] CVE-2010-1155: irssi - Irssi before 0.8.15, when SSL is used, does not verify that the server hostname ...
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.
Scope: local
bookworm: resolved (fixed in 0.8.15-1)
bullseye: resolved (fi
debian
CVE-2017-15722P4MEDIUMCVSS 5.9fixed in irssi 1.0.5-1 (bookworm)2017
CVE-2017-15722 [MEDIUM] CVE-2017-15722: irssi - In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID i...
In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
bullseye: resolved (fixed in 1.0.5-1)
forky: resolved (fixed in 1.0.5-1)
sid: resolved (fixed in 1.0.5-1)
trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2023-29132P4MEDIUMCVSS 5.3fixed in irssi 1.4.3-2 (bookworm)2023
CVE-2023-29132 [MEDIUM] CVE-2023-29132: irssi - Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stal...
Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.
Scope: local
bookworm: resolved (fixed in 1.4.3-2)
bullseye: resolved
forky: resolved (fixed in 1.4.3-2)
sid: resolved (fixed in 1.4.3-2)
trixie: resolved (fi
debian
CVE-2010-1156P4LOWCVSS 4.3fixed in irssi 0.8.15-1 (bookworm)2010
CVE-2010-1156 [MEDIUM] CVE-2010-1156: irssi - core/nicklist.c in Irssi before 0.8.15 allows remote attackers to cause a denial...
core/nicklist.c in Irssi before 0.8.15 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an attempted fuzzy nick match at the instant that a victim leaves a channel.
Scope: local
bookworm: resolved (fixed in 0.8.15-1)
bullseye: resolved (fixed in 0.8.15-1)
forky: resolved (fixed in 0.8.15-1)
si
debian
CVE-2016-7553P4LOWCVSS 3.3fixed in irssi 0.8.20-2 (bookworm)2016
CVE-2016-7553 [LOW] CVE-2016-7553: irssi - The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for t...
The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.
Scope: local
bookworm: resolved (fixed in 0.8.20-2)
bullseye: resolved (fixed in 0.8.20-2)
forky: resolved (fixed in 0.8.20-2)
debian
← Previous2 / 2