CVE-2017-9469
Summary
| CVE | CVE-2017-9469 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-07 01:29:00 UTC |
| Updated | 2019-03-14 19:07:00 UTC |
| Description | In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-3885-1 irssi |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Irssi CVE-2017-9469 Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Irssi DCC Message and File Processing Flaws Let Remote Users Cause the Target Application to Crash - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| oss-security - FYI: Irssi Security Advisory 2017/06 |
CONFIRM |
openwall.com |
Mailing List, Patch, Third Party Advisory |
| irssi.org/security/irssi_sa_2017_06.txt |
CONFIRM |
irssi.org |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500261 Alpine Linux Security Update for irssi
- 504025 Alpine Linux Security Update for irssi