CVE-2019-13045Use After Free in Irssi

CWE-416Use After Free11 documents8 sources
Severity
8.1HIGHNVD
OSV9.8
EPSS
4.8%
top 10.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 29
Latest updateMay 24

Description

Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages5 packages

NVDirssi/irssi0.8.181.0.8+2
debiandebian/irssi< irssi 1.2.1-1 (bookworm)
Debianirssi/irssi< 1.2.1-1+3
Ubuntuirssi/irssi< 0.8.19-1ubuntu1.9+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pwrg-h5j6-7f43: Irssi before 12022-05-24
OSV
irssi vulnerabilities2019-07-04
OSV
CVE-2019-13045: Irssi before 12019-06-29

📋Vendor Advisories

4
Ubuntu
Irssi vulnerabilities2019-07-04
Red Hat
irssi: use after free when sending SASL login to server2019-06-29
Microsoft
Irssi has a use after free when sending SASL login to the server2019-06-11
Debian
CVE-2019-13045: irssi - Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is ena...2019

💬Community

3
Bugzilla
CVE-2019-13045 irssi: use after free when sending SASL login to server2019-07-08
Bugzilla
CVE-2019-13045 irssi: use after free when sending SASL login to server [fedora-all]2019-07-08
Bugzilla
CVE-2019-13045 irssi: use after free when sending SASL login to server [epel-7]2019-07-08