cbcvebase.
CVE-2019-13045
published 2019-06-29

CVE-2019-13045: Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.

PriorityP345high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
3.33%
87.3th percentile
Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianirssi< irssi 1.2.1-1 (bookworm)irssi 1.2.1-1 (bookworm)
irssiirssi>= 0 < 1.2.1-11.2.1-1
irssiirssi>= 0 < 1.2.1-11.2.1-1
irssiirssi>= 0 < 1.2.1-11.2.1-1
irssiirssi>= 0 < 1.2.1-11.2.1-1
irssiirssi>= 0 < 0.8.19-1ubuntu1.90.8.19-1ubuntu1.9
irssiirssi>= 0 < 1.0.5-1ubuntu4.21.0.5-1ubuntu4.2
irssiirssi>= 0.8.18 < 1.0.81.0.8
irssiirssi>= 1.1.0 < 1.1.31.1.3
irssiirssi>= 1.2.0 < 1.2.11.2.1
msrcazl3_irssi_1.4.5-1_on_azure_linux_3.0

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.1LOW
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.