Use-after-free in Irssi - CVE-2023-29132
Published: April 3, 2023
Vulnerability identifier: #VU74276
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29132
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error when printing chat messages. A remote attacker can trigger a use-after-free error by sending multiple messages and crash the application.
Affected software
Irssi
Slackware Linux
Ubuntu
irssi (Ubuntu package)
irssi
Slackware Linux
Ubuntu
irssi (Ubuntu package)
irssi
How to mitigate CVE-2023-29132
Install updates from vendor's website.
Irssi - update to 1.4.4
irssi (Ubuntu package) - update to 1.4.2-1ubuntu1.1
irssi - update to 1.4.4
irssi (Ubuntu package) - update to 1.4.2-1ubuntu1.1
irssi - update to 1.4.4