Alpine: multiple irssi packages: security update to 1.0.6-r0

critical Tenable Self-Hosted Container Security Plugin ID 405014

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a
server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for
CVE-2017-7191. (CVE-2018-7054)

- Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove
destroyed channels from the query list, resulting in use-after-free conditions when updating the state
later on. (CVE-2017-15227)

- Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data
beyond the end of the string. (CVE-2017-15228)

- In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer
dereference. This is a separate, but similar, issue relative to CVE-2017-9468. (CVE-2017-15721)

- In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing
reads beyond the end of the string. (CVE-2017-15722)

See Also

https://security.alpinelinux.org/vuln/CVE-2017-15227

https://security.alpinelinux.org/vuln/CVE-2017-15228

https://security.alpinelinux.org/vuln/CVE-2017-15721

https://security.alpinelinux.org/vuln/CVE-2017-15722

https://security.alpinelinux.org/vuln/CVE-2017-15723

https://security.alpinelinux.org/vuln/CVE-2018-5205

https://security.alpinelinux.org/vuln/CVE-2018-5206

https://security.alpinelinux.org/vuln/CVE-2018-5207

https://security.alpinelinux.org/vuln/CVE-2018-5208

https://security.alpinelinux.org/vuln/CVE-2018-7050

https://security.alpinelinux.org/vuln/CVE-2018-7051

https://security.alpinelinux.org/vuln/CVE-2018-7052

https://security.alpinelinux.org/vuln/CVE-2018-7053

https://security.alpinelinux.org/vuln/CVE-2018-7054

Plugin Details

Severity: Critical

ID: 405014

Version: Revision 1.26

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-7054

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/22/2017

Reference Information

CVE: CVE-2017-15227, CVE-2017-15228, CVE-2017-15721, CVE-2017-15722, CVE-2017-15723, CVE-2018-5205, CVE-2018-5206, CVE-2018-5207, CVE-2018-5208, CVE-2018-7050, CVE-2018-7051, CVE-2018-7052, CVE-2018-7053, CVE-2018-7054