IRSSI Trojaned Configure File Arbitrary Access Vulnerability

BID:4831

Info

IRSSI Trojaned Configure File Arbitrary Access Vulnerability

Bugtraq ID: 4831
Class: Access Validation Error
CVE:
Remote: Yes
Local: No
Published: May 25 2002 12:00AM
Updated: May 25 2002 12:00AM
Credit: Vulnerability announced by irssi project.
Vulnerable: irssi irssi 0.8.4
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 IA-32
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- Mandriva Linux Mandrake 8.2
- Mandriva Linux Mandrake 8.1 ia64
- Mandriva Linux Mandrake 8.1
- Mandriva Linux Mandrake 8.0 ppc
- Mandriva Linux Mandrake 8.0
- Redhat Linux 7.3 i386
- Redhat Linux 7.2 ia64
- Redhat Linux 7.2 i386
- Redhat Linux 7.1 i386
- SuSE Linux 8.0 i386
- SuSE Linux 7.3 i386
- SuSE Linux 7.2 i386
Not Vulnerable:

Discussion

IRSSI Trojaned Configure File Arbitrary Access Vulnerability

irssi is a freely available, open source irc client. irssi is available for the Linux and Unix operating systems.

The server hosting irssi was compromised at some point. After being compromised, the source code to irssi was altered to include a backdoor. This backdoor allowed a user from the IP address 204.120.36.206 to remotely execute commands on the host that irssi was installed on. The source code is known to have been trojaned between the beginning of April, and end of May. Downloads of the source during this time likely contain the trojan code.

Solution / Fix

IRSSI Trojaned Configure File Arbitrary Access Vulnerability

Solution:
Backdoored source code may be identified by grepping the configure file for the string "SOCK_STREAM".

Binary downloads of the client have been reported by the irssi project as being unaffected.

A fixed version of the software is available:


irssi irssi 0.8.4

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report