Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
References
Link | Resource |
---|---|
https://irssi.org/security/irssi_sa_2019_08.txt | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2019/08/29/3 | Mailing List Third Party Advisory |
http://www.openwall.com/lists/oss-security/2019/08/29/5 | Mailing List Third Party Advisory |
https://usn.ubuntu.com/4119-1/ | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JDDRTNKDDO52CO5USJ73BE6XVG7BD4KP/ |
Information
Published : 2019-08-29 10:15
Updated : 2019-09-14 12:15
NVD link : CVE-2019-15717
Mitre link : CVE-2019-15717
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
canonical
- ubuntu_linux
irssi
- irssi