Use-after-free in Irssi - CVE-2017-15227
Published: October 22, 2017 / Updated: July 28, 2020
Irssi
Irssi.org
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.