CVE-2019-5882
moderate-risk
Published 2019-01-09
Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
Do I need to act?
-
0.52% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 7bf94c28a0a8c6be8ec5840f09a5b5d343f42374
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (5)
References (8)
Vendor Advisory
https://irssi.org/NEWS/#v1-1-2
Vendor Advisory
https://irssi.org/security/irssi_sa_2019_01.txt
Third Party Advisory
https://usn.ubuntu.com/3862-1/
Vendor Advisory
https://irssi.org/NEWS/#v1-1-2
Vendor Advisory
https://irssi.org/security/irssi_sa_2019_01.txt
Third Party Advisory
https://usn.ubuntu.com/3862-1/
46
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
2/34 · Minimal
Exposure
12/34 · Low