Use-after-free in Irssi - CVE-2019-13045
Published: July 1, 2019 / Updated: July 1, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service attack.
The vulnerability exists due to a use-after-free error when performing server reconnect with SASL authentication. A remote attacker can trigger the application to reconnect to the server (e.g. disrupt connection) that will cause application crash.
Affected software
Arch Linux
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
SUSE Linux
Opensuse
irssi (Alpine package)
irssi (Red Hat package)
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2019-13045
irssi (Alpine package) - update to 1.0.8-r0
irssi (Red Hat package) - update to 1.1.1-3.el8