CVE-2017-7191
published 2017-03-27CVE-2017-7191: The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via…
PriorityP342critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.36%
87.4th percentile
The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | irssi | < irssi 1.0.7-1 (bookworm) | irssi 1.0.7-1 (bookworm) |
| debian | irssi | < irssi 1.0.2-1 (bookworm) | irssi 1.0.2-1 (bookworm) |
| irssi | irssi | < 1.0.7 | 1.0.7 |
| irssi | irssi | <= 1.0.1 | — |
| irssi | irssi | — | — |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.2-1 | 1.0.2-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.2-1 | 1.0.2-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.2-1 | 1.0.2-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.2-1 | 1.0.2-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2qj4-5xjm-32j8: The netjoin processing in Irssi 1
ghsa_unreviewed·2022-05-17
CVE-2017-7191 [CRITICAL] CWE-416 GHSA-2qj4-5xjm-32j8: The netjoin processing in Irssi 1
The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
GHSA
GHSA-9q5h-rr4r-fvxg: An issue was discovered in Irssi before 1
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2018-7054 [CRITICAL] CWE-416 GHSA-9q5h-rr4r-fvxg: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
OSV
CVE-2018-7054: An issue was discovered in Irssi before 1
osv·2018-02-15·CVSS 9.8
CVE-2018-7054 [CRITICAL] CVE-2018-7054: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
OSV
CVE-2017-7191: The netjoin processing in Irssi 1
osv·2017-03-27·CVSS 9.8
CVE-2017-7191 [CRITICAL] CVE-2017-7191: The netjoin processing in Irssi 1
The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
Red Hat
irssi: use-after-free when a server is disconnected during netsplits
vendor_redhat·2018-02-15·CVSS 9.8
CVE-2018-7054 [CRITICAL] CWE-416 irssi: use-after-free when a server is disconnected during netsplits
irssi: use-after-free when a server is disconnected during netsplits
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
Statement: This issue did not affect the versions of Irssi as shipped with Red Hat Enterprise Linux 6 and 7, since the affected code was introduced in Irssi version 1.0.0.
Package: irssi (Red Hat Enterprise Linux 6) - Not affected
Package: irssi (Red Hat Enterprise Linux 7) - Not affected
Package: irssi (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-7054: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a...
vendor_debian·2018·CVSS 9.8
CVE-2018-7054 [CRITICAL] CVE-2018-7054: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a...
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (fixed in 1.0.7-1)
Debian
CVE-2017-7191: irssi - The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a den...
vendor_debian·2017·CVSS 9.8
CVE-2017-7191 [CRITICAL] CVE-2017-7191: irssi - The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a den...
The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.0.2-1)
bullseye: resolved (fixed in 1.0.2-1)
forky: resolved (fixed in 1.0.2-1)
sid: resolved (fixed in 1.0.2-1)
trixie: resolved (fixed in 1.0.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/97185https://github.com/irssi/irssi/commit/77b2631c78461965bc9a7414aae206b5c514e1b3https://irssi.org/security/irssi_sa_2017_03.txthttp://www.securityfocus.com/bid/97185https://github.com/irssi/irssi/commit/77b2631c78461965bc9a7414aae206b5c514e1b3https://irssi.org/security/irssi_sa_2017_03.txt
2017-03-27
Published