CVE-2019-13045: Use After Free
Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/irssito a version that resolves this vulnerability.Fixed in 1.2.3-1Fixed in 1.4.3-2Fixed in 1.4.5-1 - Upgrade
Upgrade
Irssito a version that resolves this vulnerability.Fixed in 1.0.8 - Upgrade
Upgrade
Irssito a version that resolves this vulnerability.Fixed in 1.1.3 - Upgrade
Upgrade
Irssito a version that resolves this vulnerability.Fixed in 1.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13045?
CVE-2019-13045 is classified as a medium severity vulnerability.
How do I fix CVE-2019-13045?
To fix CVE-2019-13045, upgrade Irssi to version 1.2.3-1, 1.4.3-2, or 1.4.5-1.
What versions of Irssi are affected by CVE-2019-13045?
Irssi versions before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1 are affected.
What is the impact of CVE-2019-13045?
CVE-2019-13045 can lead to a use after free condition when sending SASL login to the server.
Is CVE-2019-13045 related to SASL in Irssi?
Yes, CVE-2019-13045 occurs when SASL is enabled in Irssi.