Bugzilla – Bug 1148932
VUL-0: CVE-2019-15717: Irssi: use-after-free if the IRC server sends double CAP
Last modified: 2019-09-04 16:37:58 UTC
rh#1747346 A vulnerability was found in Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP. Reference: https://github.com/irssi/irssi/commit/5a4e7ab659aba2855895c9f43e9a7a131f4e89b3 References: https://bugzilla.redhat.com/show_bug.cgi?id=1747346 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15717 http://www.openwall.com/lists/oss-security/2019/08/29/3 http://seclists.org/oss-sec/2019/q3/183 https://irssi.org/security/irssi_sa_2019_08.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15717
openSUSE Leap is not affected, shipping Irssi 1.1.x I have opened https://build.opensuse.org/request/show/727075 greetings from Leipzig
Fixed in Factory. Closing.