PT-2009-4415 · Irssi · Irssi

Nemo

·

Published

2009-06-06

·

Updated

2024-06-15

·

CVE-2009-1959

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: irssi version 0.8.13
Description: The issue is caused by an off-by-one error in the event wallops function, which can be triggered by remote IRC servers sending an empty command. This results in a one-byte buffer under-read and a one-byte buffer underflow, leading to a denial of service (crash).
Recommendations: For irssi version 0.8.13, update to a newer version that contains a fix for this issue to prevent remote IRC servers from causing a denial of service.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1959
OPENSUSE-SU-2024:10455-1

Affected Products

Irssi