When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://usn.ubuntu.com/3527-1/ | third party advisory vendor advisory |
https://www.debian.org/security/2018/dsa-4162 | third party advisory vendor advisory |
https://irssi.org/security/irssi_sa_2018_01.txt | patch vendor advisory |