{"affected":[{"ecosystem_specific":{"binaries":[{"irssi":"1.0.5-32.1","irssi-devel":"1.0.5-32.1"}]},"package":{"ecosystem":"SUSE:Package Hub 12","name":"irssi","purl":"pkg:rpm/suse/irssi&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.5-32.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This security update for irssi to version  1.0.5 addresses the following security issues:\n\n\n* CVE-2017-15228: When installing themes with unterminated colour formatting\n  sequences, Irssi may access data beyond the end of the string.\n  This issue could have resulted in denial of service (remote crash) when \n  installing a malicious or broken theme file.\n* CVE-2017-15227: While waiting for the channel synchronisation, Irssi may\n  incorrectly fail to remove destroyed channels from the query list,\n  resulting in use after free conditions when updating the state later on.\n  This issue could have caused denial of service (remote crash) when\n  connecting to a malicious or broken ircd.\n* CVE-2017-15721: Certain incorrectly formatted DCC CTCP messages could cause\n  NULL pointer dereference.\n  This issue could have caused denial of service (remote crash) when\n  connecting to a malicious or broken ircd.\n* CVE-2017-15723: Overlong nicks or targets may result in a NULL pointer\n  dereference while splitting the message.\n  This issue could have caused denial of service (remote crash) when\n  connecting to a malicious or broken ircd.\n* CVE-2017-15722:  In certain cases Irssi may fail to verify that a Safe \n  channel ID is long enough, causing reads beyond the end of the string.","id":"openSUSE-SU-2017:2835-1","modified":"2017-10-23T07:58:14Z","published":"2017-10-23T07:58:14Z","references":[{"type":"ADVISORY","url":null},{"type":"REPORT","url":"https://bugzilla.suse.com/1064540"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15228"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15721"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15722"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15723"}],"related":["CVE-2017-15227","CVE-2017-15228","CVE-2017-15721","CVE-2017-15722","CVE-2017-15723"],"summary":"Security update for irssi","upstream":["CVE-2017-15227","CVE-2017-15228","CVE-2017-15721","CVE-2017-15722","CVE-2017-15723"]}