CVE-2017-10965: Null Pointer Dereference
Published Jul 7, 2017
·Updated
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
Affected Software
2 affected componentsFixes available
debian/irssi
1.2.0-2+deb10u11.2.3-11.4.3-21.4.5-1
Irssi irssi<=1.0.3
Remediation
Patch Available
Event History
Jul 7, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
05:15 PM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-10965?
CVE-2017-10965 has been classified with a medium severity due to the potential for denial of service.
2
How do I fix CVE-2017-10965?
To fix CVE-2017-10965, upgrade Irssi to version 1.0.4 or later, as it addresses the NULL pointer dereference issue.
3
What versions of Irssi are affected by CVE-2017-10965?
CVE-2017-10965 affects all versions of Irssi prior to 1.0.4.
4
Is CVE-2017-10965 a security vulnerability?
Yes, CVE-2017-10965 is a security vulnerability that could lead to application crashes.
5
What should I do if I can't upgrade Irssi due to CVE-2017-10965?
If you cannot upgrade, consider implementing workaround measures such as filtering received messages to avoid invalid timestamps.