==================================================================== CERT-Renater Note d'Information No. 2019/VULN248 _____________________________________________________________________ DATE : 30/08/2019 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Irssi versions prior to 1.2.2. ===================================================================== https://irssi.org/security/irssi_sa_2019_08.txt _____________________________________________________________________ IRSSI-SA-2019-08 Irssi Security Advisory [1] ============================================ CVE-2019-15717 Description ----------- (a) Use after free when receiving duplicate CAP found by Joseph Bisch. (CWE-416) CVE-2019-15717 [2] was assigned to this issue. Impact ------ May affect the stability of Irssi. Affected versions ----------------- (a) Irssi 1.2.0 and later Fixed in -------- Irssi 1.2.2 Recommended action ------------------ Upgrade to Irssi 1.2.2. We've published maintenance releases, without any new features. After installing the updated packages, one can issue the /upgrade command to load the new binary. TLS connections will require /reconnect. Mitigating facts ---------------- Most servers do not send duplicate CAP References ---------- [1] https://irssi.org/security/irssi_sa_2019_08.txt [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15717 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================