CVE-2017-5194: Use After Free
Published Mar 3, 2017
·Updated
Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message.
Affected Software
2 affected components
Irssi irssi<0.8.21
Debian Debian Linux=7.0
Remediation
Patch Available
Event History
Mar 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5194?
CVE-2017-5194 has a severity rating that allows for potential remote denial of service attacks.
2
How do I fix CVE-2017-5194?
To fix CVE-2017-5194, upgrade Irssi to version 0.8.21 or later.
3
What type of vulnerability is CVE-2017-5194?
CVE-2017-5194 is classified as a use-after-free vulnerability.
4
Who is affected by CVE-2017-5194?
CVE-2017-5194 affects users of Irssi versions prior to 0.8.21 and Debian Linux version 7.0.
5
What can attackers do with CVE-2017-5194?
Attackers can exploit CVE-2017-5194 to cause a denial of service by sending an invalid nick message.