Alpine: multiple irssi packages: security update to 1.0.4-r0 (deprecated)

high Tenable Cloud Security Plugin ID 400786

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove
destroyed channels from the query list, resulting in use-after-free conditions when updating the state
later on. (CVE-2017-15227)

- Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data
beyond the end of the string. (CVE-2017-15228)

- In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer
dereference. This is a separate, but similar, issue relative to CVE-2017-9468. (CVE-2017-15721)

- In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing
reads beyond the end of the string. (CVE-2017-15722)

- In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting
the message. (CVE-2017-15723)

See Also

https://git.alpinelinux.org/aports/commit/?id=21cc65393156af4cd058b7c06a3f0dfc6dbaa239

https://git.alpinelinux.org/aports/commit/?id=b8bf4317707fbf2f48603161b652e1f20dba65f0

Plugin Details

Severity: High

ID: 400786

Version: Revision 1.22

Type: Local

Published: 8/16/2023

Updated: 1/17/2024

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2017-15723

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/23/2017

Vulnerability Publication Date: 10/22/2017

Reference Information

CVE: CVE-2017-15227, CVE-2017-15228, CVE-2017-15721, CVE-2017-15722, CVE-2017-15723