Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 693106 (CVE-2019-15717) - <net-irc/irssi-1.2.2 - Use after free when receiving duplicate CAP (CWE-416)
Summary: <net-irc/irssi-1.2.2 - Use after free when receiving duplicate CAP (CWE-416)
Status: RESOLVED FIXED
Alias: CVE-2019-15717
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://irssi.org/security/irssi_sa_2...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-08-30 06:27 UTC by Jeroen Roovers (RETIRED)
Modified: 2019-08-31 05:14 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers (RETIRED) gentoo-dev 2019-08-30 06:27:55 UTC
IRSSI-SA-2019-08 Irssi Security Advisory [1]
============================================
CVE-2019-15717

Description
-----------

(a) Use after free when receiving duplicate CAP found by Joseph Bisch.
    (CWE-416)

    CVE-2019-15717 [2] was assigned to this issue.


Impact
------

May affect the stability of Irssi.


Affected versions
-----------------

(a) Irssi 1.2.0 and later


Fixed in
--------

Irssi 1.2.2


Recommended action
------------------

Upgrade to Irssi 1.2.2. We've published maintenance releases, without
any new features.

After installing the updated packages, one can issue the /upgrade
command to load the new binary. TLS connections will require /reconnect.


Mitigating facts
----------------

Most servers do not send duplicate CAP



References
----------

[1] https://irssi.org/security/irssi_sa_2019_08.txt
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15717