MGASA-2017-0043

Source
https://advisories.mageia.org/MGASA-2017-0043.html
Import Source
https://advisories.mageia.org/MGASA-2017-0043.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0043
Published
2017-02-07T13:34:44Z
Modified
2026-04-16T04:27:32.048991Z
Summary
Updated irssi-otr packages fix security vulnerability
Details

It was discovered that irssi-otr had a flaw in handing data returned by libotr. After the initiation of the OTR session only the first line was sent as a PRIVMSG, while additional data would be sent as raw commands to the IRC server. The additional data would ordinarily be a human-readable HTML-formatted instruction message from libotr, a fixed string. However this is a minor security concern and the remediation avoids further security issues.

References
Credits

Affected packages

Mageia:5 / irssi-otr

Package

Name
irssi-otr
Purl
pkg:rpm/mageia/irssi-otr?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2-1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0043.json"