Debian Security Advisory
DSA-3672-1 irssi -- security update
- Date Reported:
- 21 Sep 2016
- Affected Packages:
- irssi
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-7044, CVE-2016-7045.
- More information:
-
Gabriel Campana and Adrien Guinet from Quarkslab discovered two remotely exploitable crash and heap corruption vulnerabilities in the format parsing code in Irssi, a terminal based IRC client.
For the stable distribution (jessie), these problems have been fixed in version 0.8.17-1+deb8u1.
We recommend that you upgrade your irssi packages.