The client of the future https://irssi.org
  • C 90.6%
  • XS 3.4%
  • Perl 2.1%
  • Meson 2%
  • Prolog 1.5%
  • Other 0.4%
Find a file
Acts1631 a5bd495733 otr: cap reassembled multi-fragment message size (remote DoS)
enqueue_otr_fragment() reassembles ?OTR: multi-fragment OTR messages
into a per-peer heap buffer (opc->full_msg), grown by realloc on every
fragment that does not end with the OTR end tag '.'. The buffer has no
total size limit.

A remote IRC user can open a reassembly by sending a query PRIVMSG whose
body begins with ?OTR: and lacks the trailing '.', then keep sending
further PRIVMSGs: each is appended to opc->full_msg (roughly one
IRC-line-length worth of bytes per fragment) with no bound, growing it
until the victim irssi is OOM-killed. No OTR session is required -- the
peer context is created lazily by otr_find_context(..., create=1) on
first contact in otr_receive(), and sig_message_private
(signal_add_first on "message private") feeds every query PRIVMSG
straight to otr_receive()/enqueue_otr_fragment().

Add an OTR_REASM_MAX_SIZE (256 KiB) cap on the total reassembled size.
When appending a fragment would exceed it, free and reset the
reassembly state and return OTR_MSG_ERROR, on both the
subsequent-fragment and initial-fragment paths. 256 KiB is far above
any legitimate OTR message, so there is no functional regression.
2026-07-06 10:41:55 -04:00
.github/workflows Add muon fmt GitHub Actions workflow 2026-01-26 21:02:10 -08:00
.obs test OBS workflow 2022-05-19 14:37:59 +02:00
docs run meson formatter 2026-01-25 22:07:44 +01:00
fuzz-support Fix some glib deprecation warnings 2019-10-31 23:49:40 +01:00
scripts run meson formatter 2026-01-25 22:07:44 +01:00
src otr: cap reassembled multi-fragment message size (remote DoS) 2026-07-06 10:41:55 -04:00
subprojects up glib wrap 2026-01-23 21:21:10 +01:00
tests run meson formatter 2026-01-25 22:07:44 +01:00
themes run meson formatter 2026-01-25 22:07:44 +01:00
utils fix clang-format-xs boot code 2026-01-24 20:53:29 +01:00
.clang-format fix clang formatting 2021-04-01 21:21:06 +02:00
.gitattributes Add .gitattributes to ensure all shell scripts have LF as eol-style. 2016-01-31 20:49:59 +02:00
.gitignore good-bye and thanks, autotools 2022-02-19 21:44:10 +01:00
.muon_fmt.ini run meson formatter 2026-01-25 22:07:44 +01:00
AUTHORS Add OTR support. 2018-02-26 23:32:57 +01:00
COPYING Update FSF address. 2007-05-08 17:51:51 +00:00
INSTALL Add a few more compile dependencies to INSTALL document 2026-01-23 22:17:39 +01:00
irssi-icon.png New icon by ditCh. 2008-03-04 17:46:11 +00:00
irssi.conf new SHELP default alias 2022-04-24 15:40:20 +02:00
MANIFEST.in Add some missing files to make-dist 2022-02-20 18:55:45 +01:00
meson.build Format root meson.build 2026-01-26 21:02:10 -08:00
meson_options.txt remove deprecated defines 2022-02-20 17:33:36 +01:00
NEWS Merge tag '1.4.5' into integrate/1.4.5 2023-10-01 19:19:33 +02:00
README.md Update minimum required Perl version in readme 2024-04-01 22:10:35 +02:00
TODO Add todo for gnutls. 2008-03-30 13:53:33 +00:00

Irssi

Build Status

Irssi is a modular text mode chat client. It comes with IRC support built in, and there are third party ICB, SILC, XMPP (Jabber), PSYC and Quassel protocol modules available.

irssi

Download information

Development source installation

Ninja 1.8 and Meson 0.53

git clone https://github.com/irssi/irssi
cd irssi
meson Build
ninja -C Build && sudo ninja -C Build install

Release source installation

  • Download release
  • Verify signature
tar xJf irssi-*.tar.xz
cd irssi-*
meson Build
ninja -C Build && sudo ninja -C Build install

Requirements

See the INSTALL file for details

Documentation

Themes

Scripts

Modules

Security information

Please report security issues to staff@irssi.org. Thanks!

Bugs / Suggestions / Contributing

Check the GitHub issues if it is already listed in there; if not, open an issue on GitHub or send a mail to staff@irssi.org.

Irssi is always looking for developers. Feel free to submit patches through GitHub pull requests.

You can also contact the Irssi developers in #irssi on irc.libera.chat.