First published: Fri Jul 07 2017(Updated: )
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/irssi | 1.2.0-2+deb10u1 1.2.3-1 1.4.3-2 1.4.5-1 | |
Irssi Irssi | <=1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10965 has been classified with a medium severity due to the potential for denial of service.
To fix CVE-2017-10965, upgrade Irssi to version 1.0.4 or later, as it addresses the NULL pointer dereference issue.
CVE-2017-10965 affects all versions of Irssi prior to 1.0.4.
Yes, CVE-2017-10965 is a security vulnerability that could lead to application crashes.
If you cannot upgrade, consider implementing workaround measures such as filtering received messages to avoid invalid timestamps.