An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
References
Link | Resource |
---|---|
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291 | Issue Tracking Patch Third Party Advisory |
https://irssi.org/security/irssi_sa_2017_07.txt | Patch Vendor Advisory |
https://www.debian.org/security/2017/dsa-4016 | |
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291 | Issue Tracking Patch Third Party Advisory |
https://irssi.org/security/irssi_sa_2017_07.txt | Patch Vendor Advisory |
https://www.debian.org/security/2017/dsa-4016 |
Configurations
History
21 Nov 2024, 03:06
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://irssi.org/security/irssi_sa_2017_07.txt - Patch, Vendor Advisory | |
References | () https://www.debian.org/security/2017/dsa-4016 - |
Information
Published : 2017-07-07 14:29
Updated : 2024-11-21 03:06
NVD link : CVE-2017-10966
Mitre link : CVE-2017-10966
CVE.ORG link : CVE-2017-10966
JSON object : View
Products Affected
irssi
- irssi
CWE
CWE-416
Use After Free