[ASA-201908-20] irssi: arbitrary code execution
Arch Linux Security Advisory ASA-201908-20 ========================================== Severity: High Date : 2019-08-29 CVE-ID : CVE-2019-15717 Package : irssi Type : arbitrary code execution Remote : Yes Link : Summary ======= The package irssi before version 1.2.2-1 is vulnerable to arbitrary code execution. Resolution ========== Upgrade to 1.2.2-1. # pacman -Syu "irssi>=1.2.2-1" The problem has been fixed upstream in version 1.2.2. Workaround ========== None. Description =========== Use after free when receiving duplicate CAP found. Impact ====== A remote malicious IRC server can cause a denial of service and potentially arbitrary code execution by sending a duplicate CAP message. References ==========