NULL pointer dereference in Irssi - CVE-2017-10965
Published: July 10, 2017 / Updated: July 11, 2017
Vulnerability identifier: #VU7400
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10965
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference error when parsing messages with invalid time stamps in Irssi. A remote attacker can send a specially crafted message and crash the affected server.
The vulnerability exists due to NULL pointer dereference error when parsing messages with invalid time stamps in Irssi. A remote attacker can send a specially crafted message and crash the affected server.
Affected software
Irssi
Arch Linux
Slackware Linux
Ubuntu
Fedora
irssi (Alpine package)
irssi
Arch Linux
Slackware Linux
Ubuntu
Fedora
irssi (Alpine package)
irssi
How to mitigate CVE-2017-10965
Update to version 1.0.4.
irssi (Alpine package) - update to 0.8.21-r2
irssi - addressed in versions 1.0.4-1.fc25, 1.0.4-1.fc26
irssi - addressed in versions 1.0.4-1.fc25, 1.0.4-1.fc26