CVE-2018-7054
published 2018-02-15CVE-2018-7054: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this…
PriorityP343critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.43%
82.3th percentile
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | irssi | < irssi 1.0.7-1 (bookworm) | irssi 1.0.7-1 (bookworm) |
| irssi | irssi | < 1.0.7 | 1.0.7 |
| irssi | irssi | — | — |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 1.0.7-1 | 1.0.7-1 |
| irssi | irssi | >= 0 < 0.8.15-5ubuntu3.5 | 0.8.15-5ubuntu3.5 |
| irssi | irssi | >= 0 < 0.8.19-1ubuntu1.9 | 0.8.19-1ubuntu1.9 |
| irssi | irssi | >= 0 < 0.8.19-1ubuntu1.7 | 0.8.19-1ubuntu1.7 |
| irssi | irssi | >= 0 < 1.0.5-1ubuntu4.2 | 1.0.5-1ubuntu4.2 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9q5h-rr4r-fvxg: An issue was discovered in Irssi before 1
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2018-7054 [CRITICAL] CWE-416 GHSA-9q5h-rr4r-fvxg: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
OSV
irssi vulnerabilities
osv·2019-07-04·CVSS 9.8
CVE-2018-7054 [CRITICAL] irssi vulnerabilities
irssi vulnerabilities
It was discovered that Irssi incorrectly handled certain disconnections.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-7054)
It was discovered that Irssi incorrectly handled certain requests.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2019-13045)
OSV
irssi vulnerabilities
osv·2018-03-06·CVSS 7.5
CVE-2018-7050 [HIGH] irssi vulnerabilities
irssi vulnerabilities
It was discovered that Irssi incorrectly handled certain empty
nick names. An attacker could possibly use this issue to cause a denial
of service. (CVE-2018-7050)
It was discovered that Irssi incorrectly handled certain nick names.
An attacker could possibly use this to access sensitive information.
(CVE-2018-7051)
It was discovered that Irssi incorrectly handled an increase in the
number of windows. An attacker could possibly use this issue to cause
a denial of service. (CVE-2018-7052)
It was discovered that Irssi incorrectly handled certain messages.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 17.10. (CVE-2018-7053)
It was discovered that Irssi incorrectly
OSV
CVE-2018-7054: An issue was discovered in Irssi before 1
osv·2018-02-15·CVSS 9.8
CVE-2018-7054 [CRITICAL] CVE-2018-7054: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
Ubuntu
Irssi vulnerabilities
vendor_ubuntu·2019-07-04·CVSS 9.8
CVE-2018-7054 [CRITICAL] Irssi vulnerabilities
Title: Irssi vulnerabilities
Summary: Several security issues were fixed in Irssi.
It was discovered that Irssi incorrectly handled certain disconnections.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-7054)
It was discovered that Irssi incorrectly handled certain requests.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2019-13045)
Instructions: After a standard system update you need to restart Irssi to make all the necessary changes.
Ubuntu
Irssi vulnerabilities
vendor_ubuntu·2018-03-06·CVSS 7.5
CVE-2018-7050 [HIGH] Irssi vulnerabilities
Title: Irssi vulnerabilities
Summary: Several security issues were fixed in Irssi.
It was discovered that Irssi incorrectly handled certain empty
nick names. An attacker could possibly use this issue to cause a denial
of service. (CVE-2018-7050)
It was discovered that Irssi incorrectly handled certain nick names.
An attacker could possibly use this to access sensitive information.
(CVE-2018-7051)
It was discovered that Irssi incorrectly handled an increase in the
number of windows. An attacker could possibly use this issue to cause
a denial of service. (CVE-2018-7052)
It was discovered that Irssi incorrectly handled certain messages.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 17
Red Hat
irssi: use-after-free when a server is disconnected during netsplits
vendor_redhat·2018-02-15·CVSS 9.8
CVE-2018-7054 [CRITICAL] CWE-416 irssi: use-after-free when a server is disconnected during netsplits
irssi: use-after-free when a server is disconnected during netsplits
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
Statement: This issue did not affect the versions of Irssi as shipped with Red Hat Enterprise Linux 6 and 7, since the affected code was introduced in Irssi version 1.0.0.
Package: irssi (Red Hat Enterprise Linux 6) - Not affected
Package: irssi (Red Hat Enterprise Linux 7) - Not affected
Package: irssi (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-7054: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a...
vendor_debian·2018·CVSS 9.8
CVE-2018-7054 [CRITICAL] CVE-2018-7054: irssi - An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a...
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (fixed in 1.0.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7054 irssi: use-after-free when a server is disconnected during netsplits
bugzilla·2018-02-16·CVSS 9.8
CVE-2018-7054 [CRITICAL] CVE-2018-7054 irssi: use-after-free when a server is disconnected during netsplits
CVE-2018-7054 irssi: use-after-free when a server is disconnected during netsplits
An issue was discovered in Irssi 1.0.0 and later. There is a use-after-free when a server is disconnected during netsplits.
References:
https://irssi.org/security/irssi_sa_2018_02.txt
Discussion:
Created irssi tracking bugs for this issue:
Affects: fedora-all [bug 1546318]
---
Upstream patches:
https://github.com/irssi/irssi/commit/a6cae91cecba2e8cf11ed779c5da5a229472575c
https://github.com/irssi/irssi/commit/38ba3ca2c40fc8ccccec8dc3f360c4087e7dd498
---
Statement:
This issue did not affect the versions of Irssi as shipped with Red Hat Enterprise Linux 6 and 7, since the affected code was introduced in Irssi version 1.0.0.
Bugzilla
CVE-2018-7054 irssi: use-after-free when a server is disconnected during netsplits [fedora-all]
bugzilla·2018-02-16·CVSS 9.8
CVE-2018-7054 [CRITICAL] CVE-2018-7054 irssi: use-after-free when a server is disconnected during netsplits [fedora-all]
CVE-2018-7054 irssi: use-after-free when a server is disconnected during netsplits [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
http://openwall.com/lists/oss-security/2018/02/15/1https://irssi.org/security/irssi_sa_2018_02.txthttps://usn.ubuntu.com/3590-1/https://usn.ubuntu.com/4046-1/https://www.debian.org/security/2018/dsa-4162http://openwall.com/lists/oss-security/2018/02/15/1https://irssi.org/security/irssi_sa_2018_02.txthttps://usn.ubuntu.com/3590-1/https://usn.ubuntu.com/4046-1/https://www.debian.org/security/2018/dsa-4162
2018-02-15
Published