NULL pointer dereference in Irssi - CVE-2017-15723
Published: October 22, 2017 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message. A remote attacker can perform a denial of service (DoS) attack.
Affected software
Arch Linux
Slackware Linux
irssi (Alpine package)
How to mitigate CVE-2017-15723
irssi (Alpine package) - addressed in versions 1.0.5-r0, 1.0.6-r0