The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.
CVSS Details
- CVSS 3.0 Base Score: 3.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade irssi | Mar 31, 2017 | Oct 13, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade irssi | Feb 22, 2021 | Feb 27, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade irssi | Apr 30, 2021 | Feb 27, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade irssi | Feb 3, 2021 | Feb 27, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Feb 27, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 22, 2016 |
| Suse | — | Upgrade irssi-develUpgrade irssi | Nov 3, 2016 | Oct 13, 2016 |
| Ubuntu | — | Upgrade irssi | Feb 2, 2017 | Oct 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub