Joseph Bisch discovered that Irssi incorrectly handled incomplete escape codes. If a user were tricked into using malformed commands or opening malformed files, an attacker could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5205)
Joseph Bisch discovered that Irssi incorrectly handled settings the channel topic without specifying a sender. A malicious IRC server could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5206)
Joseph Bisch discovered that Irssi incorrectly handled incomplete variable arguments. If a user were tricked into using malformed commands or opening malformed files, an attacker could use this issue to cause Irssi to crash, resulting in a denial of service. (CVE-2018-5207)
Joseph Bisch discovered that Irssi incorrectly handled completing certain strings. An attacker could use this issue to cause Irssi to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-5208)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "0.8.19-1ubuntu1.6", "binary_name": "irssi" }, { "binary_version": "0.8.19-1ubuntu1.6", "binary_name": "irssi-dbg" }, { "binary_version": "0.8.19-1ubuntu1.6", "binary_name": "irssi-dbgsym" }, { "binary_version": "0.8.19-1ubuntu1.6", "binary_name": "irssi-dev" }, { "binary_version": "0.8.19-1ubuntu1.6", "binary_name": "irssi-dev-dbgsym" } ] }