Summary
The remote host is missing an update to irssi-text announced via advisory DSA 157-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20157-1
Insight
The IRC client irssi is vulnerable to a denial of service condition.
The problem occurs when a user attempts to join a channel that has an overly long topic description. When a certain string is appended to the topic, irssi will crash.
This problem has been fixed in version 0.8.4-3.1 for the current stable stable distribution (woody) and in version 0.8.5-2 for the unstable distribution (sid). The old stable distribution (potato) is not affected, since the corresponding portions of code are not present. The same applies to irssi-gnome and irssi-gtk, which don't seem to be affected as well.
We recommend that you upgrade your irssi-text package.
Severity
Classification
-
CVE CVE-2002-0983 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities