Use-after-free in Irssi - CVE-2019-13045

 

Use-after-free in Irssi - CVE-2019-13045

Published: July 1, 2019 / Updated: July 1, 2019


Vulnerability identifier: #VU18945
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13045
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service attack.

The vulnerability exists due to a use-after-free error when performing server reconnect with SASL authentication. A remote attacker can trigger the application to reconnect to the server (e.g. disrupt connection) that will cause application crash.



Affected software

Irssi
Arch Linux
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
SUSE Linux
Opensuse
irssi (Alpine package)
irssi (Red Hat package)
SUSE Package Hub for SUSE Linux Enterprise

How to mitigate CVE-2019-13045

Install updates from vendor's website.

Irssi - addressed in versions 1.0.8, 1.1.3, 1.2.1
irssi (Alpine package) - update to 1.0.8-r0
irssi (Red Hat package) - update to 1.1.1-3.el8

External References

Related Security Bulletins