ASA-2019-00006 – Irssi: Use-after-free when hidden lines were expired from the scroll buffer


Allele Security Alert

ASA-2019-00006

Identifier(s)

ASA-2019-00006, IRSSI-SA-2019-01, CVE-2019-5882

Title

Use-after-free when hidden lines were expired from the scroll buffer

Vendor(s)

The Irssi Team

Product(s)

Irssi

Affected version(s)

Irssi 1.1.0 and later

Fixed version(s)

Irssi 1.1.2

Proof of concept

Unknown

Description

Irssi 1.1.x before 1.1.2 has an use-after-free when hidden lines are expired from the scroll buffer.

Technical details

Unknown

Credits

Unknown

Reference(s)

IRSSI-SA-2019-01 Irssi Security Advisory [1]
https://irssi.org/security/irssi_sa_2019_01.txt

invalidate startline and bottom_startline when hidden #948
https://github.com/irssi/irssi/pull/948

invalidate startline and bottom_startline when hidden
https://github.com/irssi/irssi/pull/948/commits/8684ccb45c267fdeaaa779fce9323047aa5a9e38

Irssi NEWS
https://irssi.org/NEWS/#v1-1-2

Irssi 1.1.2 Released
https://irssi.org/2019/01/09/irssi-1.1.2-released/

IRSSI-SA-2019-01 Irssi Security Advisory [1]
https://irssi.org/security/html/irssi_sa_2019_01/

CVE-2019-5882
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5882

CVE-2019-5882
https://nvd.nist.gov/vuln/detail/CVE-2019-5882

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: January 11, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.