Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2017/dsa-4016 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2017/12/msg00022.html | mailing list |
https://irssi.org/security/irssi_sa_2017_10.txt | patch vendor advisory mitigation |
http://openwall.com/lists/oss-security/2017/10/22/4 | mailing list patch mitigation third party advisory |