Irssi Denial of Service and SSL Hostname Verification Security Bypass Vulnerabilities
BID:39377
Info
Irssi Denial of Service and SSL Hostname Verification Security Bypass Vulnerabilities
| Bugtraq ID: | 39377 |
| Class: | Design Error |
| CVE: |
CVE-2010-1155 CVE-2010-1156 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2010 12:00AM |
| Updated: | Jun 21 2010 04:19PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux x86_64 -current Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Red Hat Fedora 13 Red Hat Fedora 12 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 irssi irssi 0.8.14 irssi irssi 0.8.13 irssi irssi 0.8.11 irssi irssi 0.8.9 irssi irssi 0.8.8 irssi irssi 0.8.7 irssi irssi 0.8.6 irssi irssi 0.8.5 irssi irssi 0.8.4 irssi irssi 0.8.10rc5 |
| Not Vulnerable: |
irssi irssi 0.8.15 |
Discussion
Irssi Denial of Service and SSL Hostname Verification Security Bypass Vulnerabilities
Irssi is prone to a denial-of-service vulnerability and a security-bypass vulnerability.
An attacker can exploit these issues to gain unauthorized access to the affected computer and to crash the affected application.
Versions prior to Irssi 0.8.15 are vulnerable.
Irssi is prone to a denial-of-service vulnerability and a security-bypass vulnerability.
An attacker can exploit these issues to gain unauthorized access to the affected computer and to crash the affected application.
Versions prior to Irssi 0.8.15 are vulnerable.
Exploit / POC
Irssi Denial of Service and SSL Hostname Verification Security Bypass Vulnerabilities
An attacker may exploit the security-bypass issue by using readily available network utilities. Currently we are not aware of any working exploits for the denial-of-service issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker may exploit the security-bypass issue by using readily available network utilities. Currently we are not aware of any working exploits for the denial-of-service issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Irssi Denial of Service and SSL Hostname Verification Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
Slackware Linux x86_64 -current
Slackware Linux 12.0
Mandriva Linux Mandrake 2009.1 x86_64
Slackware Linux -current
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 8.10 i386
Slackware Linux 12.2
Ubuntu Ubuntu Linux 9.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 9.10 lpia
Ubuntu Ubuntu Linux 9.04 sparc
Mandriva Linux Mandrake 2010.0
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 9.04 powerpc
Ubuntu Ubuntu Linux 8.10 lpia
Slackware Linux 13.0 x86_64
Mandriva Linux Mandrake 2010.0 x86_64
Slackware Linux 12.1
Ubuntu Ubuntu Linux 9.04 i386
Ubuntu Ubuntu Linux 9.04 lpia
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 9.10 i386
Slackware Linux 13.0
Ubuntu Ubuntu Linux 9.10 amd64
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu Ubuntu Linux 9.04 amd64
Slackware Linux 11.0
irssi irssi 0.8.10rc5
Mandriva Linux Mandrake 2009.1
Ubuntu Ubuntu Linux 8.10 amd64
irssi irssi 0.8.11
irssi irssi 0.8.13
irssi irssi 0.8.14
irssi irssi 0.8.4
irssi irssi 0.8.5
irssi irssi 0.8.6
irssi irssi 0.8.7
irssi irssi 0.8.8
irssi irssi 0.8.9
Slackware Linux 10.1
Slackware Linux 10.2
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
-
Ubuntu irssi-dev_0.8.14-1ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.14-1ubuntu1.1_ sparc.deb -
Ubuntu irssi_0.8.14-1ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.14-1ubuntu1.1_spar c.deb
Slackware Linux x86_64 -current
-
Slackware irssi-0.8.15-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ n/irssi-0.8.15-x86_64-1.txz
Slackware Linux 12.0
-
Slackware irssi-0.8.15-i486-1_slack12.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ irssi-0.8.15-i486-1_slack12.0.tgz
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva irssi-0.8.12-4.2mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-devel-0.8.12-4.2mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-perl-0.8.12-4.2mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
Slackware Linux -current
-
Slackware irssi-0.8.15-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/ir ssi-0.8.15-i486-1.txz
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu irssi-dev_0.8.12-3ubuntu3.2_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-3ubuntu3.2_ powerpc.deb -
Ubuntu irssi_0.8.12-3ubuntu3.2_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-3ubuntu3.2_powe rpc.deb
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu irssi-dev_0.8.12-4ubuntu2.2_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-4ubuntu2.2_ powerpc.deb -
Ubuntu irssi_0.8.12-4ubuntu2.2_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-4ubuntu2.2_powe rpc.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu irssi-dev_0.8.12-3ubuntu3.2_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-3ubuntu3.2_ sparc.deb -
Ubuntu irssi_0.8.12-3ubuntu3.2_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-3ubuntu3.2_spar c.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu irssi-dev_0.8.12-4ubuntu2.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.12-4 ubuntu2.2_i386.deb -
Ubuntu irssi_0.8.12-4ubuntu2.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.12-4ubun tu2.2_i386.deb
Slackware Linux 12.2
-
Slackware irssi-0.8.15-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ irssi-0.8.15-i486-1_slack12.2.tgz
Ubuntu Ubuntu Linux 9.10 powerpc
-
Ubuntu irssi-dev_0.8.14-1ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.14-1ubuntu1.1_ powerpc.deb -
Ubuntu irssi_0.8.14-1ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.14-1ubuntu1.1_powe rpc.deb
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu irssi-dev_0.8.12-3ubuntu3.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.12-3 ubuntu3.2_amd64.deb -
Ubuntu irssi_0.8.12-3ubuntu3.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.12-3ubun tu3.2_amd64.deb
Ubuntu Ubuntu Linux 9.10 lpia
-
Ubuntu irssi-dev_0.8.14-1ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.14-1ubuntu1.1_ lpia.deb -
Ubuntu irssi_0.8.14-1ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.14-1ubuntu1.1_lpia .deb
Ubuntu Ubuntu Linux 9.04 sparc
-
Ubuntu irssi-dev_0.8.12-6ubuntu1.2_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-6ubuntu1.2_ sparc.deb -
Ubuntu irssi_0.8.12-6ubuntu1.2_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-6ubuntu1.2_spar c.deb
Mandriva Linux Mandrake 2010.0
-
Mandriva irssi-0.8.14-2.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-devel-0.8.14-2.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-perl-0.8.14-2.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu irssi-dev_0.8.12-3ubuntu3.2_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-3ubuntu3.2_ lpia.deb -
Ubuntu irssi_0.8.12-3ubuntu3.2_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-3ubuntu3.2_lpia .deb
Ubuntu Ubuntu Linux 9.04 powerpc
-
Ubuntu irssi-dev_0.8.12-6ubuntu1.2_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-6ubuntu1.2_ powerpc.deb -
Ubuntu irssi_0.8.12-6ubuntu1.2_powerpc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-6ubuntu1.2_powe rpc.deb
Ubuntu Ubuntu Linux 8.10 lpia
-
Ubuntu irssi-dev_0.8.12-4ubuntu2.2_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-4ubuntu2.2_ lpia.deb -
Ubuntu irssi_0.8.12-4ubuntu2.2_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-4ubuntu2.2_lpia .deb
Slackware Linux 13.0 x86_64
-
Slackware irssi-0.8.15-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/irssi-0.8.15-x86_64-1_slack13.0.txz
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva irssi-0.8.14-2.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-devel-0.8.14-2.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-perl-0.8.14-2.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Slackware Linux 12.1
-
Slackware irssi-0.8.15-i486-1_slack12.1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/ irssi-0.8.15-i486-1_slack12.1.tgz
Ubuntu Ubuntu Linux 9.04 i386
-
Ubuntu irssi-dev_0.8.12-6ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.12-6 ubuntu1.2_i386.deb -
Ubuntu irssi_0.8.12-6ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.12-6ubun tu1.2_i386.deb
Ubuntu Ubuntu Linux 9.04 lpia
-
Ubuntu irssi-dev_0.8.12-6ubuntu1.2_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-6ubuntu1.2_ lpia.deb -
Ubuntu irssi_0.8.12-6ubuntu1.2_lpia.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-6ubuntu1.2_lpia .deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu irssi-dev_0.8.12-4ubuntu2.2_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi-dev_0.8.12-4ubuntu2.2_ sparc.deb -
Ubuntu irssi_0.8.12-4ubuntu2.2_sparc.deb
http://ports.ubuntu.com/pool/main/i/irssi/irssi_0.8.12-4ubuntu2.2_spar c.deb
Ubuntu Ubuntu Linux 9.10 i386
-
Ubuntu irssi-dev_0.8.14-1ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.14-1 ubuntu1.1_i386.deb -
Ubuntu irssi_0.8.14-1ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.14-1ubun tu1.1_i386.deb
Slackware Linux 13.0
-
Slackware irssi-0.8.15-i486-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/ irssi-0.8.15-i486-1_slack13.0.txz
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu irssi-dev_0.8.14-1ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.14-1 ubuntu1.1_amd64.deb -
Ubuntu irssi_0.8.14-1ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.14-1ubun tu1.1_amd64.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu irssi-dev_0.8.12-3ubuntu3.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.12-3 ubuntu3.2_i386.deb -
Ubuntu irssi_0.8.12-3ubuntu3.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.12-3ubun tu3.2_i386.deb
Ubuntu Ubuntu Linux 9.04 amd64
-
Ubuntu irssi-dev_0.8.12-6ubuntu1.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.12-6 ubuntu1.2_amd64.deb -
Ubuntu irssi_0.8.12-6ubuntu1.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.12-6ubun tu1.2_amd64.deb
Slackware Linux 11.0
-
Slackware irssi-0.8.15-i486-1_slack11.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ irssi-0.8.15-i486-1_slack11.0.tgz
irssi irssi 0.8.10rc5
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
Mandriva Linux Mandrake 2009.1
-
Mandriva irssi-0.8.12-4.2mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-devel-0.8.12-4.2mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva irssi-perl-0.8.12-4.2mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu irssi-dev_0.8.12-4ubuntu2.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi-dev_0.8.12-4 ubuntu2.2_amd64.deb -
Ubuntu irssi_0.8.12-4ubuntu2.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/i/irssi/irssi_0.8.12-4ubun tu2.2_amd64.deb
irssi irssi 0.8.11
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.13
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.14
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.4
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.5
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.6
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.7
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.8
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
irssi irssi 0.8.9
-
irssi irssi-0.8.15.tar.gz
http://www.irssi.org/files/irssi-0.8.15.tar.gz
Slackware Linux 10.1
-
Slackware irssi-0.8.15-i486-1_slack10.1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ irssi-0.8.15-i486-1_slack10.1.tgz
Slackware Linux 10.2
-
Slackware irssi-0.8.15-i486-1_slack10.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ irssi-0.8.15-i486-1_slack10.2.tgz
References
Irssi Denial of Service and SSL Hostname Verification Security Bypass Vulnerabilities
References:
References:
- Irssi 0.8.15 Released (Irssi)
- irssi Home Page (irssi)