Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_name": "irssi", "binary_version": "0.8.15-5ubuntu3.1" }, { "binary_name": "irssi-dbgsym", "binary_version": "0.8.15-5ubuntu3.1" }, { "binary_name": "irssi-dev", "binary_version": "0.8.15-5ubuntu3.1" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_name": "irssi", "binary_version": "0.8.19-1ubuntu1.3" }, { "binary_name": "irssi-dbg", "binary_version": "0.8.19-1ubuntu1.3" }, { "binary_name": "irssi-dbgsym", "binary_version": "0.8.19-1ubuntu1.3" }, { "binary_name": "irssi-dev", "binary_version": "0.8.19-1ubuntu1.3" }, { "binary_name": "irssi-dev-dbgsym", "binary_version": "0.8.19-1ubuntu1.3" } ] }