CVE-2016-7553

low
Published 2017-02-27 · Modified 2026-05-13
CVSS v3
3.3
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2
2.1
VIR risk
3.3

Description

The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.

Predictions

Exploit likelihood
34%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-7553

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://irssi.org/security/buf_pl_sa_2016.txt

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://github.com/irssi/scripts.irssi.org/commit/f1b1eb154baa684fad5d65bf4dff79c8ded8b65a

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.openwall.com/lists/oss-security/2016/09/26/4

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.openwall.com/lists/oss-security/2016/09/24/1

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.8.20-2
debian debianbullseyefixed0.8.20-2
debian debianforkyfixed0.8.20-2
debian debiansidfixed0.8.20-2
debian debiantrixiefixed0.8.20-2

Application impact

VendorProductVersionsFixed
irssibuf.pl{"endIncluding":"2.13"}

References

CWEs

CWE-275

Verify integrity in audit chain (admin only). AS-IS.