4.3
CVSSv2

CVE-2010-1156

Published: 16/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

core/nicklist.c in Irssi prior to 0.8.15 allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an attempted fuzzy nick match at the instant that a victim leaves a channel.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

irssi irssi 0.8.5

irssi irssi 0.8.8

irssi irssi 0.8.7

irssi irssi 0.8.13

irssi irssi 0.8.12

irssi irssi 0.8.11

irssi irssi 0.8.3

irssi irssi 0.8.2

irssi irssi 0.8.6

irssi irssi 0.8.10

irssi irssi 0.8.1

irssi irssi 0.8.0

irssi irssi 0.8.4

irssi irssi 0.8.9

irssi irssi

irssi irssi 0.8.14

Vendor Advisories

USN-929-1 fixed vulnerabilities in irssi The upstream changes introduced a regression when using irssi with SSL and an IRC proxy This update fixes the problem ...
It was discovered that irssi did not perform certificate host validation when using SSL connections An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications (CVE-2010-1155) ...