Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bugzilla DB migration completed. Please report issues to Infra team via email via infra@gentoo.org or IRC
Bug 624982 - net-irc/irssi-1.0.3 CVE-2017-10965, CVE-2017-10966
Summary: net-irc/irssi-1.0.3 CVE-2017-10965, CVE-2017-10966
Status: RESOLVED DUPLICATE of bug 624100
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Linux bug wranglers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-07-14 12:08 UTC by Andrey Ovcharov
Modified: 2017-07-14 12:10 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andrey Ovcharov 2017-07-14 12:08:17 UTC
https://nvd.nist.gov/vuln/detail/CVE-2017-10965

"An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer."

https://nvd.nist.gov/vuln/detail/CVE-2017-10966

"An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table."
Comment 1 Andrey Ovcharov 2017-07-14 12:10:47 UTC

*** This bug has been marked as a duplicate of bug 624100 ***