Use-after-free in Irssi - CVE-2019-5882
Published: January 13, 2019
Vulnerability identifier: #VU16953
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5882
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct DoS attack.
The vulnerability exists due to a use-after-free error when hidden lines are expired from the scroll buffer. A remote attacker can trigger memory corruption and cause the service to crash.
Affected software
Irssi
Arch Linux
Slackware Linux
Opensuse
Fedora
irssi (Alpine package)
irssi
Arch Linux
Slackware Linux
Opensuse
Fedora
irssi (Alpine package)
irssi
How to mitigate CVE-2019-5882
Update to version 1.1.2.
Irssi - update to 1.1.2
irssi (Alpine package) - update to 1.1.2-r0
irssi - addressed in versions 1.1.2-1.fc28, 1.1.2-1.fc29
irssi (Alpine package) - update to 1.1.2-r0
irssi - addressed in versions 1.1.2-1.fc28, 1.1.2-1.fc29