Debian Security Advisory

DLA-1318-1 irssi -- LTS security update

Date Reported:
26 Mar 2018
Affected Packages:
irssi
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-7051.
More information:

It was discovered that there was an issue in the irssi IRC client where certain nick names could result in out-of-bounds access when printing theme strings.

For Debian 7 Wheezy, this issue has been fixed in irssi version 0.8.15-5+deb7u6. It was incorrectly missing from the upload of 0.8.15-5+deb7u5 announced as part of DLA-1289-1. Thanks to Ben Hutchings and Matus Uhlhar.

We recommend that you upgrade your irssi packages.