CVE-2023-29132
published 2023-04-14CVE-2023-29132: Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted…
PriorityP423medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.81%
52.8th percentile
Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | irssi | < irssi 1.4.3-2 (bookworm) | irssi 1.4.3-2 (bookworm) |
| irssi | irssi | >= 0 < 1.4.3-2 | 1.4.3-2 |
| irssi | irssi | >= 0 < 1.4.3-2 | 1.4.3-2 |
| irssi | irssi | >= 0 < 1.4.3-2 | 1.4.3-2 |
| irssi | irssi | >= 1.3.0 < 1.4.4 | 1.4.4 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Irssi vulnerability
vendor_ubuntu·2023-04-10
CVE-2023-29132 Irssi vulnerability
Title: Irssi vulnerability
Summary: Irssi could be made to crash in specific scenarios.
It was discovered that Irssi incorrectly handled certain internal routines.
An attacker could possibly use this issue to cause a crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
irssi: a use after free possible under special circumstances
vendor_redhat·2023-03-30·CVSS 5.3
CVE-2023-29132 [MEDIUM] CWE-416 irssi: a use after free possible under special circumstances
irssi: a use after free possible under special circumstances
Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.
A flaw was found in the Irssi package. When Irssi prints a message while another message is being printed, the list that keeps track of Irssi variables for use in statusbar/message patterns is incorrectly cleaned up, leading to a use-after-free condition.
Statement: The versions of Irssi as shipped in Red Hat Enterprise Linux 6, 7, 8, and 9 are not affected by this vulnerability. Only Irssi versions 1.3.0 and higher are vulnerable.
Package: irssi (Red Hat Enterprise Linux 6) - Not affected
Package: irssi (Red Hat Enter
Debian
CVE-2023-29132: irssi - Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stal...
vendor_debian·2023·CVSS 5.3
CVE-2023-29132 [MEDIUM] CVE-2023-29132: irssi - Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stal...
Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.
Scope: local
bookworm: resolved (fixed in 1.4.3-2)
bullseye: resolved
forky: resolved (fixed in 1.4.3-2)
sid: resolved (fixed in 1.4.3-2)
trixie: resolved (fixed in 1.4.3-2)
GHSA
GHSA-rx4q-gwv4-r27p: Irssi 1
ghsa_unreviewed·2023-04-14
CVE-2023-29132 [MEDIUM] CWE-416 GHSA-rx4q-gwv4-r27p: Irssi 1
Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.
OSV
CVE-2023-29132: Irssi 1
osv·2023-04-14·CVSS 5.3
CVE-2023-29132 [MEDIUM] CVE-2023-29132: Irssi 1
Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-14
Published