CVE-2017-5356: Debian Linux

High severity, CVSS 7.5. EPSS: 4.8% chance of exploitation in the next 30 days.

Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).

Affected products

  • Debian Debian Linux: version 7.0 only
  • Irssi Irssi: before 0.8.21 (fixed in 0.8.21)

Published 2017-03-03. Last modified 2026-06-17.