UbuntuUpdates.org

Bugs fixes in "irssi"

Origin Bug number Title Date fixed
CVE CVE-2017-15723 In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message. 2017-10-26
CVE CVE-2017-15722 In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string. 2017-10-26
CVE CVE-2017-15721 In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue 2017-10-26
CVE CVE-2017-15228 Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string. 2017-10-26
CVE CVE-2017-15227 Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting i 2017-10-26
CVE CVE-2017-10966 An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free t 2017-10-26
CVE CVE-2017-10965 An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer. 2017-10-26
CVE CVE-2017-1096 IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod 2017-10-26
CVE CVE-2017-9469 In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memo 2017-06-12
CVE CVE-2017-9468 In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can 2017-06-12
CVE CVE-2017-9469 In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memo 2017-06-12
CVE CVE-2017-9468 In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can 2017-06-12
CVE CVE-2017-5356 Irssi out of bounds read in format string 2017-02-01
CVE CVE-2017-5196 Out of bounds read in certain incomplete character sequences 2017-02-01
CVE CVE-2017-5195 Out of bounds read in certain incomplete control codes 2017-02-01
CVE CVE-2017-5194 Use after free when receiving invalid nick message 2017-02-01
CVE CVE-2017-5193 NULL pointer dereference in the nickcmp function 2017-02-01
CVE CVE-2016-7553 Information disclosure vulnerability in buf.pl 2017-02-01
CVE CVE-2017-5356 Irssi out of bounds read in format string 2017-02-01
CVE CVE-2017-5196 Out of bounds read in certain incomplete character sequences 2017-02-01



About   -   Send Feedback to @ubuntu_updates