summaryrefslogtreecommitdiff
path: root/security/irssi_sa_2017_03.txt
diff options
context:
space:
mode:
authorAilin Nemui <ailin@z30a.localdomain>2018-02-14 00:54:53 +0100
committerAilin Nemui <ailin@z30a.localdomain>2018-02-14 23:06:37 +0100
commit813c12822a68983ab42905f5af364dcc9c7ffcdd (patch)
treeb8e8986b0f1bfad0e20809b78b0e9a1a3235ce16 /security/irssi_sa_2017_03.txt
parent21f070359fe8174573deea8fea19ccd95dc3e51d (diff)
downloadirssi.github.io-813c12822a68983ab42905f5af364dcc9c7ffcdd.zip
enable security collections
Diffstat (limited to 'security/irssi_sa_2017_03.txt')
-rw-r--r--security/irssi_sa_2017_03.txt57
1 files changed, 0 insertions, 57 deletions
diff --git a/security/irssi_sa_2017_03.txt b/security/irssi_sa_2017_03.txt
deleted file mode 100644
index d155884..0000000
--- a/security/irssi_sa_2017_03.txt
+++ /dev/null
@@ -1,57 +0,0 @@
-use after free condition during netjoin processing [1]
-======================================================
-CWE Classification: CWE-416
-
-
-CVE-2017-7191 [2] was assigned to this bug
-
-
-Description
------------
-
-Use after free while producing list of netjoins (CWE-416)
-
-This issue was found and reported to us by APic.
-
-
-Impact
-------
-
-This issue usually leads to segmentation faults. Targeted code
-execution should be difficult.
-
-
-Affected versions
------------------
-
-Irssi up to and including 1.0.1
-
-We believe Irssi 0.8.21 and prior are not affected since a different
-code path causes the netjoins to be flushed prior to reaching the use
-after free condition.
-
-
-Fixed in
---------
-
-Irssi 1.0.2
-
-
-Recommended action
-------------------
-
-Upgrade to Irssi 1.0.2. Irssi 1.0.2 is a maintenance release
-without any new features.
-
-
-Patch
------
-
-https://github.com/irssi/irssi/commit/77b2631c78461965bc9a7414aae206b5c514e1b3
-
-
-References
-----------
-
-[1] https://irssi.org/security/irssi_sa_2017_03.txt
-[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7191