Use-after-free in Irssi - CVE-2017-10966
Published: July 10, 2017 / Updated: July 11, 2017
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to use-after-free error when incorrectly using GHashTable interface while updating internal nick list. A remote unauthenticated attacker can create a specially crafted nick name and crash the affected server or execute arbitrary code.
Successful exploitation of the vulnerability may result in remote code execution.
Affected software
Arch Linux
Slackware Linux
Ubuntu
Fedora
irssi (Alpine package)
irssi
How to mitigate CVE-2017-10966
irssi - addressed in versions 1.0.4-1.fc25, 1.0.4-1.fc26