CVE-2018-7054
Published: 15 February 2018
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
Notes
Author | Note |
---|---|
leosilva | from debian, netsplit code was introduced in 1.0.0 trusty and xenial are not-affected. |
Priority
CVSS 3 base score: 9.8
Status
Package | Release | Status |
---|---|---|
irssi Launchpad, Ubuntu, Debian |
artful |
Released
(1.0.4-1ubuntu2.3)
|
bionic |
Released
(1.0.5-1ubuntu4.2)
|
|
cosmic |
Released
(1.1.1-1ubuntu1)
|
|
disco |
Released
(1.1.1-1ubuntu2)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was not-affected [code not present])
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
|
|
Patches: other: https://github.com/irssi/irssi/commit/5c5ed64180a6b76315ee7b8c6000ee64ad5877a7 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7054
- https://irssi.org/security/irssi_sa_2018_02.txt
- https://github.com/irssi/irssi/commit/7605f67f95b6ee1ac26dd8fb7f3121f319497943
- https://github.com/irssi/irssi/commit/fa8508404f4c4a02749cae5148662e2322c2abf0
- https://github.com/irssi/irssi/commit/a4f99ae746efb121185fe76c392a64d743a9eb92
- http://openwall.com/lists/oss-security/2018/02/15/1
- https://github.com/irssi/irssi/issues/819
- https://ubuntu.com/security/notices/USN-3590-1
- https://ubuntu.com/security/notices/USN-4046-1
- NVD
- Launchpad
- Debian