VDB
CVE-2018-7054
CVE-2018-7054
PUBLISHED
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.
EPSS 1.17% · 78.9th percentile
Risk Scores
EPSS Score
1.17%
78.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | irssi | 0, 1.0.4-1ubuntu2, 1.0.4-1ubuntu3 |
Timeline
- Feb 15, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 5, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-7054 third-party-advisory
- https://irssi.org/security/irssi_sa_2018_02.txt third-party-advisory
- https://github.com/irssi/irssi/commit/7605f67f95b6ee1ac26dd8fb7f3121f319497943 third-party-advisory
- https://github.com/irssi/irssi/commit/fa8508404f4c4a02749cae5148662e2322c2abf0 third-party-advisory
- https://github.com/irssi/irssi/commit/a4f99ae746efb121185fe76c392a64d743a9eb92 third-party-advisory
- http://openwall.com/lists/oss-security/2018/02/15/1 third-party-advisory
- https://github.com/irssi/irssi/issues/819 third-party-advisory
- https://ubuntu.com/security/notices/USN-3590-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-4046-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-7054 third-party-advisory