The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.8.15-5ubuntu3.1", "binary_name": "irssi" }, { "binary_version": "0.8.15-5ubuntu3.1", "binary_name": "irssi-dbgsym" }, { "binary_version": "0.8.15-5ubuntu3.1", "binary_name": "irssi-dev" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.8.19-1ubuntu1.3", "binary_name": "irssi" }, { "binary_version": "0.8.19-1ubuntu1.3", "binary_name": "irssi-dbg" }, { "binary_version": "0.8.19-1ubuntu1.3", "binary_name": "irssi-dbgsym" }, { "binary_version": "0.8.19-1ubuntu1.3", "binary_name": "irssi-dev" }, { "binary_version": "0.8.19-1ubuntu1.3", "binary_name": "irssi-dev-dbgsym" } ], "availability": "No subscription required" }