Use-after-free in Irssi - CVE-2017-15227
Published: October 22, 2017 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.
Affected software
Arch Linux
Slackware Linux
irssi (Alpine package)
How to mitigate CVE-2017-15227
irssi (Alpine package) - addressed in versions 1.0.5-r0, 1.0.6-r0