Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU32047
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2017-15228
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
MitigationInstall update from vendor's website.
Vulnerable software versionsIrssi: 1.0.0 - 1.0.4
CPE2.3https://openwall.com/lists/oss-security/2017/10/22/4
https://irssi.org/security/irssi_sa_2017_10.txt
https://lists.debian.org/debian-lts-announce/2017/12/msg00022.html
https://www.debian.org/security/2017/dsa-4016
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.