VulnerabilityModified
CVE-2017-10966
This would then result in use-after-free conditions on each access of the hash table.
CRITICAL 9.8EPSS 2.94%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.94% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- irssi/irssi
- Source
- cve@mitre.org
References
- https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291Issue Tracking, Patch, Third Party Advisory
- https://irssi.org/security/irssi_sa_2017_07.txtPatch, Vendor Advisory
- https://www.debian.org/security/2017/dsa-4016
- https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291Issue Tracking, Patch, Third Party Advisory
- https://irssi.org/security/irssi_sa_2017_07.txtPatch, Vendor Advisory
- https://www.debian.org/security/2017/dsa-4016
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.