PatchSiren cyber security CVE debrief
CVE-2017-5193 Debian CVE debrief
CVE-2017-5193 is a remotely triggerable denial-of-service issue in Irssi versions before 0.8.21. A message without a nick can drive the nickcmp function into a NULL pointer dereference, crashing the client. The published record classifies this as a high-severity availability problem with no evidence in the corpus of data exposure or code execution.
- Vendor
- Debian
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
Anyone running Irssi before 0.8.21 should care, especially users who connect to untrusted or public IRC networks where malformed messages may be encountered. Package maintainers and security teams responsible for Linux distributions that ship Irssi should also verify they have the fixed release or backported patch.
Technical summary
NVD describes the flaw as a NULL pointer dereference in Irssi's nickcmp function, reachable when processing a message without a nick. The affected version range in the supplied corpus is Irssi before 0.8.21. The CVSS vector indicates network reachability, low attack complexity, no privileges, no user interaction, and a high availability impact.
Defensive priority
High for environments that still run affected Irssi clients, because the flaw is remotely triggerable and can crash the application. Priority is lower only if you have already confirmed Irssi 0.8.21 or later, or a vetted downstream backport, is deployed everywhere.
Recommended defensive actions
- Upgrade Irssi to version 0.8.21 or later, or install the vendor/distribution security fix referenced in the advisory corpus.
- Verify package versions across all systems that run Irssi and confirm no older build remains in use.
- If you rely on downstream packaging, check that the fix is present in your distro's security update stream before deferring remediation.
- Review crash logs or support tickets for unexpected Irssi exits that may align with NULL pointer dereference behavior in nickcmp.
- Track upstream and distribution advisories for any backported fix guidance relevant to your platform.
Evidence notes
The debrief is based on the supplied CVE description, which states that nickcmp in Irssi before 0.8.21 can be crashed by a message without a nick. NVD data in the corpus assigns CWE-476 and CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, and the CPE criteria explicitly mark irssi versions ending before 0.8.21 as vulnerable. The vendor advisory and OSS-security reference are included as corroborating sources. No exploit code or reproduction steps are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5193 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5193
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5193 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5193
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://irssi.org/security/irssi_sa_2017_01.txt
[email protected] - Patch, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2017/12/msg00022.html
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201701-45
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.