CVE-2017-10966
published 2017-07-07CVE-2017-10966: An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick…
PriorityP343critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.94%
85.5th percentile
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | irssi | < irssi 1.0.4-1 (bookworm) | irssi 1.0.4-1 (bookworm) |
| irssi | irssi | <= 1.0.3 | — |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 0.8.15-5ubuntu3.3 | 0.8.15-5ubuntu3.3 |
| irssi | irssi | >= 0 < 0.8.19-1ubuntu1.5 | 0.8.19-1ubuntu1.5 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3jw8-77gg-583w: An issue was discovered in Irssi before 1
ghsa_unreviewed·2022-05-17
CVE-2017-10966 [CRITICAL] CWE-416 GHSA-3jw8-77gg-583w: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
OSV
irssi vulnerabilities
osv·2017-10-26·CVSS 9.8
CVE-2017-10965 [CRITICAL] irssi vulnerabilities
irssi vulnerabilities
Brian Carpenter discovered that Irssi incorrectly handled messages with
invalid time stamps. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-10965)
Brian Carpenter discovered that Irssi incorrectly handled the internal nick
list. A malicious IRC server could use this issue to cause Irssi to crash,
resulting in a denial of service. (CVE-2017-10966)
Joseph Bisch discovered that Irssi incorrectly removed destroyed channels
from the query list. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-15227)
Hanno Böck discovered that Irssi incorrectly handled themes. If a user were
tricked into using a malicious theme, a attacker could use this issu
OSV
CVE-2017-10966: An issue was discovered in Irssi before 1
osv·2017-07-07·CVSS 9.8
CVE-2017-10966 [CRITICAL] CVE-2017-10966: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
Ubuntu
Irssi vulnerabilities
vendor_ubuntu·2017-10-26·CVSS 9.8
CVE-2017-10965 [CRITICAL] Irssi vulnerabilities
Title: Irssi vulnerabilities
Summary: Several security issues were fixed in Irssi.
Brian Carpenter discovered that Irssi incorrectly handled messages with
invalid time stamps. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-10965)
Brian Carpenter discovered that Irssi incorrectly handled the internal nick
list. A malicious IRC server could use this issue to cause Irssi to crash,
resulting in a denial of service. (CVE-2017-10966)
Joseph Bisch discovered that Irssi incorrectly removed destroyed channels
from the query list. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-15227)
Hanno Böck discovered that Irssi incorrectly handled themes. If a user were
tricke
Red Hat
irssi: Use-after-free while updating the internal nick list
vendor_redhat·2017-07-05·CVSS 9.8
CVE-2017-10966 [CRITICAL] CWE-416 irssi: Use-after-free while updating the internal nick list
irssi: Use-after-free while updating the internal nick list
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
Package: irssi (Red Hat Enterprise Linux 6) - Will not fix
Package: irssi (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-10966: irssi - An issue was discovered in Irssi before 1.0.4. While updating the internal nick ...
vendor_debian·2017·CVSS 9.8
CVE-2017-10966 [CRITICAL] CVE-2017-10966: irssi - An issue was discovered in Irssi before 1.0.4. While updating the internal nick ...
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
Scope: local
bookworm: resolved (fixed in 1.0.4-1)
bullseye: resolved (fixed in 1.0.4-1)
forky: resolved (fixed in 1.0.4-1)
sid: resolved (fixed in 1.0.4-1)
trixie: resolved (fixed in 1.0.4-1)
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2017-10966: Heap-use-after-free in Irssi <1.0.4
hackerone·2019-10-14·CVSS 9.8
CVE-2017-10966 [CRITICAL] CVE-2017-10966: Heap-use-after-free in Irssi <1.0.4
CVE-2017-10966: Heap-use-after-free in Irssi <1.0.4
35 days after reading https://irssi.org/2017/05/12/fuzzing-irssi/, I was able to trigger a heap-use-after-free in irssi 1.0.2.
Timeline:
Report to vendor: 16 June 2017
Acknowledge by vendor: 16 June 2017
Fixed by vendor: 7 July 2017
Advisory:
http://seclists.org/oss-sec/2017/q3/80
Patch:
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206
```
./irssi < test001
CAP LS
NICK root
USER root root /dev/stdin :root
MODE +i
WHOIS root
WHO +00000000000000000000o00
==30112==ERROR: AddressSanitizer: heap-use-after-free on address 0x607000008100 at pc 0x0000006d3a48 bp 0x7ffdd447b320 sp 0x7ffdd447b318
READ of size 8 at 0x607000008100 thread T0
#0 0x6d3a47 in nicklist_remove_hash /root/irssi-1.0.2/src/core/nicklist.c:455:30
#
Bugzilla
CVE-2017-10966 irssi: Use-after-free while updating the internal nick list
bugzilla·2017-07-20·CVSS 9.8
CVE-2017-10966 [CRITICAL] CVE-2017-10966 irssi: Use-after-free while updating the internal nick list
CVE-2017-10966 irssi: Use-after-free while updating the internal nick list
An issue was discovered in Irssi. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
Upstream patch:
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291
External References:
https://irssi.org/security/irssi_sa_2017_07.txt
Discussion:
Lowering severity based on the fact that a rogue IRC server would be needed to take advantage of the vulnerability.
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291https://irssi.org/security/irssi_sa_2017_07.txthttps://www.debian.org/security/2017/dsa-4016https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291https://irssi.org/security/irssi_sa_2017_07.txthttps://www.debian.org/security/2017/dsa-4016
2017-07-07
Published