Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 595172 (CVE-2016-7553) - <net-irc/irssi-0.8.20-r1: Information disclosure in buf.pl
Summary: <net-irc/irssi-0.8.20-r1: Information disclosure in buf.pl
Status: RESOLVED FIXED
Alias: CVE-2016-7553
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-09-26 09:27 UTC by Agostino Sarubbo
Modified: 2016-11-21 12:27 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-09-26 09:27:46 UTC
From ${URL} :

An information disclosure vulnerability was found in the buf.pl core script for irssi. Other users on the same machine may be able to retrieve the whole window contents after /UPGRADE when the buf.pl script is loaded. Furthermore, this dump of the windows 
contents is never removed afterwards.

External References:

https://irssi.org/2016/09/22/buf.pl-update/

Upstream fix:

https://github.com/irssi/scripts.irssi.org/commit/f1b1eb154baa684fad5d65bf4dff79c8ded8b65a

References:

http://seclists.org/oss-sec/2016/q3/605


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Sven Wegener gentoo-dev 2016-09-26 22:10:58 UTC
I've just added 0.8.20-r1 to the tree, including the fix. I have forward-ported all the keywords, as only architecture-independent perl code has been changed.

- The shipped script is not in use by default
- The script stores the world-readable scrollbuffer file in ~/.irssi
- If it does not exist, irssi creates the ~/.irssi directory with mode 0700 (since at least commit c95034c6de1bf72536595e1e3431d8ec64b9880e from 2000-04-26)

I consider this a low-risk issue.
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-11-21 12:27:51 UTC
GLSA Vote: No