An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade irssi | Feb 21, 2018 | Feb 15, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 15, 2018 |
| Debian | — | Upgrade irssi | Apr 3, 2018 | Feb 15, 2018 |
| Freebsd | — | Upgrade irssi | Feb 20, 2018 | Feb 19, 2018 |
| Oracle Solaris | — | Upgrade network/chat/irssi to version 1.0.7-0.175.3.31.0.1.0 on Solaris 11.3 | Apr 18, 2018 | Feb 15, 2018 |
| Suse | — | Upgrade irssiUpgrade irssi-devel | Feb 20, 2018 | Feb 15, 2018 |
| Ubuntu | — | Upgrade irssi | Apr 25, 2018 | Feb 15, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub