Ubuntu Security Notice 4046-1 - It was discovered that Irssi incorrectly handled certain disconnections. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. It was discovered that Irssi incorrectly handled certain requests. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. Various other issues were also addressed.
68d7b29c8dd907ca7c5958cc1370cc0536b54f6945db12b7f899498beab3f8e9
==========================================================================
Ubuntu Security Notice USN-4046-1
July 04, 2019
irssi vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Irssi.
Software Description:
- irssi: terminal based IRC client
Details:
It was discovered that Irssi incorrectly handled certain disconnections.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-7054)
It was discovered that Irssi incorrectly handled certain requests.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2019-13045)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.04:
irssi 1.2.0-2ubuntu1.1
Ubuntu 18.10:
irssi 1.1.1-1ubuntu1.2
Ubuntu 18.04 LTS:
irssi 1.0.5-1ubuntu4.2
Ubuntu 16.04 LTS:
irssi 0.8.19-1ubuntu1.9
After a standard system update you need to restart Irssi to make all the necessary changes.
References:
https://usn.ubuntu.com/4046-1
CVE-2018-7054, CVE-2019-13045
Package Information:
https://launchpad.net/ubuntu/+source/irssi/1.2.0-2ubuntu1.1
https://launchpad.net/ubuntu/+source/irssi/1.1.1-1ubuntu1.2
https://launchpad.net/ubuntu/+source/irssi/1.0.5-1ubuntu4.2
https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.9