Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-7054

Опубликовано: 15 фев. 2018
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.

Отчет

This issue did not affect the versions of Irssi as shipped with Red Hat Enterprise Linux 6 and 7, since the affected code was introduced in Irssi version 1.0.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6irssiNot affected
Red Hat Enterprise Linux 7irssiNot affected
Red Hat Enterprise Linux 8irssiNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1546223irssi: use-after-free when a server is disconnected during netsplits

EPSS

Процентиль: 83%
0.02383
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.

CVSS3: 9.8
nvd
больше 8 лет назад

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.

CVSS3: 9.8
debian
больше 8 лет назад

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. ...

CVSS3: 9.8
github
больше 4 лет назад

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость IRC-клиента Irssi для операционных систем Debian GNU/Linux и Ubuntu, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 83%
0.02383
Низкий

3.7 Low

CVSS3