← Vulnerability feed

Vulnerability record · CVE-2017-5195 · published 3 March 2017

CVE-2017-5195: Irssi out-of-bounds read vulnerability

Irssi · Irssi

Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.

7.5 CVSS 3.0 High EPSS 5.5% · top 7.5% CWE-125 · Out-of-bounds read
7.5CVSS 3.0 base score, v2 5.0
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2017/01/06/1 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/95310 Issue TrackingThird Party AdvisoryVDB Entry
https://irssi.org/security/irssi_sa_2017_01.txt PatchVendor Advisory
https://security.gentoo.org/glsa/201701-45 Third Party Advisory
http://www.openwall.com/lists/oss-security/2017/01/06/1 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/95310 Issue TrackingThird Party AdvisoryVDB Entry
https://irssi.org/security/irssi_sa_2017_01.txt PatchVendor Advisory
https://security.gentoo.org/glsa/201701-45 Third Party Advisory

Track CVE-2017-5195 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1840Irssi vulnerabilityirssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to acc…EPSS 2.8%9.8CVE-2019-15717Irssi use after free vulnerabilityIrssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.EPSS 2.5%9.8CVE-2019-5882Irssi use after free vulnerabilityIrssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.EPSS 2.5%9.8CVE-2018-7053Irssi use after free vulnerabilityAn issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected orde…EPSS 2.4%9.8CVE-2018-7054Irssi use after free vulnerabilityAn issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE:…EPSS 2.4%9.8CVE-2018-5206Irssi null pointer dereference vulnerabilityWhen the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.EPSS 2.2%9.8CVE-2018-5208Irssi memory buffer overflow vulnerabilityIn Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.EPSS 2.4%9.8CVE-2017-10965Irssi null pointer dereference vulnerabilityAn issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2017-5195), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.