Description
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
References (3)
Core 3
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2017/dsa-4016
Patch, Vendor Advisory x_refsource_confirm
https://irssi.org/security/irssi_sa_2017_07.txt
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291
Scores
CVSS v3
9.8
EPSS
0.0078
EPSS Percentile
73.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (1)
irssi/irssi
< 1.0.3
Published
Jul 07, 2017
Tracked Since
Feb 18, 2026