Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00030.html
http://packetstormsecurity.com/files/153480/Slackware-Security-Advisory-irssi-Updates.html
http://www.openwall.com/lists/oss-security/2019/06/29/1
http://www.securityfocus.com/bid/108998
https://github.com/irssi/irssi/commit/d23b0d22cc611e43c88d99192a59f413f951a955
https://irssi.org/security/irssi_sa_2019_06.txt
Source: MITRE
Published: 2019-06-29
Updated: 2019-07-03
Type: CWE-416
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.1
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.2
Severity: HIGH