Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 624982

Summary: net-irc/irssi-1.0.3 CVE-2017-10965, CVE-2017-10966
Product: Gentoo Linux Reporter: Andrey Ovcharov <sudormrfhalt>
Component: Current packagesAssignee: Gentoo Linux bug wranglers <bug-wranglers>
Status: RESOLVED DUPLICATE    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Andrey Ovcharov 2017-07-14 12:08:17 UTC
https://nvd.nist.gov/vuln/detail/CVE-2017-10965

"An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer."

https://nvd.nist.gov/vuln/detail/CVE-2017-10966

"An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table."
Comment 1 Andrey Ovcharov 2017-07-14 12:10:47 UTC

*** This bug has been marked as a duplicate of bug 624100 ***