← Vulnerability feed

Vulnerability record · CVE-2009-1959 · published 8 June 2009

CVE-2009-1959: Irssi vulnerability

Irssi · Irssi

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

5.0 CVSS 2.0 Medium EPSS 8.4% · top 5.2% CWE-189 · CWE-189
5.0CVSS 2.0 base score
8.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.irssi.org/index.php?do=details&task_id=662 ExploitVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
http://secunia.com/advisories/35685
http://secunia.com/advisories/35812
http://secunia.com/advisories/36152
http://www.irssi.org/ChangeLog ExploitVendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:133
http://www.openwall.com/lists/oss-security/2009/05/29/3
http://www.securityfocus.com/bid/35399
http://www.securitytracker.com/id?1022410
http://www.ubuntu.com/usn/usn-800-1
http://www.vupen.com/english/advisories/2009/1596
http://xorl.wordpress.com/2009/05/28/irssi-event_wallops-off-by-one-readwrite/ Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/51184
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00146.html
http://bugs.irssi.org/index.php?do=details&task_id=662 ExploitVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
http://secunia.com/advisories/35685
http://secunia.com/advisories/35812
http://secunia.com/advisories/36152
http://www.irssi.org/ChangeLog ExploitVendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:133
http://www.openwall.com/lists/oss-security/2009/05/29/3
http://www.securityfocus.com/bid/35399
http://www.securitytracker.com/id?1022410
http://www.ubuntu.com/usn/usn-800-1
http://www.vupen.com/english/advisories/2009/1596
http://xorl.wordpress.com/2009/05/28/irssi-event_wallops-off-by-one-readwrite/ Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/51184
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00146.html

Track CVE-2009-1959 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1840Irssi vulnerabilityirssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to acc…EPSS 2.8%9.8CVE-2019-15717Irssi use after free vulnerabilityIrssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.EPSS 2.5%9.8CVE-2019-5882Irssi use after free vulnerabilityIrssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.EPSS 2.5%9.8CVE-2018-7053Irssi use after free vulnerabilityAn issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected orde…EPSS 2.4%9.8CVE-2018-7054Irssi use after free vulnerabilityAn issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE:…EPSS 2.4%9.8CVE-2018-5206Irssi null pointer dereference vulnerabilityWhen the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.EPSS 2.2%9.8CVE-2018-5208Irssi memory buffer overflow vulnerabilityIn Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.EPSS 2.4%9.8CVE-2017-10965Irssi null pointer dereference vulnerabilityAn issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2009-1959), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.