CVE-2018-7053
published 2018-02-15CVE-2018-7053: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
PriorityP338critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.45%
82.5th percentile
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | irssi | < irssi 1.0.7-1 (bookworm) | irssi 1.0.7-1 (bookworm) |
| irssi | irssi | < 1.0.7 | 1.0.7 |
| irssi | irssi | — | — |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 0.8.15-5ubuntu3.5 | 0.8.15-5ubuntu3.5 |
| irssi | irssi | >= 0 < 0.8.19-1ubuntu1.7 | 0.8.19-1ubuntu1.7 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jfgj-q49c-3779: An issue was discovered in Irssi before 1
ghsa_unreviewed·2022-05-14
CVE-2018-7053 [CRITICAL] CWE-416 GHSA-jfgj-q49c-3779: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
OSV
irssi vulnerabilities
osv·2018-03-06·CVSS 7.5
CVE-2018-7050 [HIGH] irssi vulnerabilities
irssi vulnerabilities
It was discovered that Irssi incorrectly handled certain empty
nick names. An attacker could possibly use this issue to cause a denial
of service. (CVE-2018-7050)
It was discovered that Irssi incorrectly handled certain nick names.
An attacker could possibly use this to access sensitive information.
(CVE-2018-7051)
It was discovered that Irssi incorrectly handled an increase in the
number of windows. An attacker could possibly use this issue to cause
a denial of service. (CVE-2018-7052)
It was discovered that Irssi incorrectly handled certain messages.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 17.10. (CVE-2018-7053)
It was discovered that Irssi incorrectly
OSV
CVE-2018-7053: An issue was discovered in Irssi before 1
osv·2018-02-15·CVSS 9.8
CVE-2018-7053 [CRITICAL] CVE-2018-7053: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
Ubuntu
Irssi vulnerabilities
vendor_ubuntu·2018-03-06·CVSS 7.5
CVE-2018-7050 [HIGH] Irssi vulnerabilities
Title: Irssi vulnerabilities
Summary: Several security issues were fixed in Irssi.
It was discovered that Irssi incorrectly handled certain empty
nick names. An attacker could possibly use this issue to cause a denial
of service. (CVE-2018-7050)
It was discovered that Irssi incorrectly handled certain nick names.
An attacker could possibly use this to access sensitive information.
(CVE-2018-7051)
It was discovered that Irssi incorrectly handled an increase in the
number of windows. An attacker could possibly use this issue to cause
a denial of service. (CVE-2018-7052)
It was discovered that Irssi incorrectly handled certain messages.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 17
Red Hat
irssi: use-after-free when SASL messages are received in unexpected order
vendor_redhat·2018-02-13·CVSS 9.8
CVE-2018-7053 [CRITICAL] CWE-416 irssi: use-after-free when SASL messages are received in unexpected order
irssi: use-after-free when SASL messages are received in unexpected order
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
A use-after-free was found in the way Irssi, version 0.8.18 and later, handled out of order SASL messages sent by an IRC server. A remote attacker, who controls an IRC server, could crash the application by exploiting this flaw.
Statement: This issue did not affect the versions of Irssi as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include support for SASL.
Package: irssi (Red Hat Enterprise Linux 6) - Not affected
Package: irssi (Red Hat Enterprise Linux 7) - Not affected
Package: irssi (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-7053: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a...
vendor_debian·2018·CVSS 9.8
CVE-2018-7053 [CRITICAL] CVE-2018-7053: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a...
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (fixed in 1.0.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7053 irssi: use-after-free when SASL messages are received in unexpected order
bugzilla·2018-02-16·CVSS 9.8
CVE-2018-7053 [CRITICAL] CVE-2018-7053 irssi: use-after-free when SASL messages are received in unexpected order
CVE-2018-7053 irssi: use-after-free when SASL messages are received in unexpected order
A use-after-free was discovered in Irssi 0.8.18 and later when SASL messages
from a server are received in unexpected order. A remote attacker, in control of
an IRC server, could cause a crash in Irssi clients by leveraging this flaw.
Upstream commit:
https://github.com/irssi/irssi/commit/b8d3301d34f383f039071214872570385de1bb59
Upstream patch:
https://github.com/irssi/irssi/commit/36564717c9f701e3a339da362ab46d220d27e0c1
References:
https://irssi.org/security/irssi_sa_2018_02.txt
Discussion:
Created irssi tracking bugs for this issue:
Affects: fedora-all [bug 1546227]
---
Statement:
This issue did not affect the versions of Irssi as shipped with Red Hat Enterprise Linux 6 and 7 as they did no
Bugzilla
CVE-2018-7053 irssi: use-after-free when SASL messages are received in unexpected order [fedora-all]
bugzilla·2018-02-16·CVSS 9.8
CVE-2018-7053 [CRITICAL] CVE-2018-7053 irssi: use-after-free when SASL messages are received in unexpected order [fedora-all]
CVE-2018-7053 irssi: use-after-free when SASL messages are received in unexpected order [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
http://openwall.com/lists/oss-security/2018/02/15/1https://irssi.org/security/irssi_sa_2018_02.txthttps://usn.ubuntu.com/3590-1/https://www.debian.org/security/2018/dsa-4162http://openwall.com/lists/oss-security/2018/02/15/1https://irssi.org/security/irssi_sa_2018_02.txthttps://usn.ubuntu.com/3590-1/https://www.debian.org/security/2018/dsa-4162
2018-02-15
Published