CVE-2017-9468: Null Pointer Dereference
Published Jun 7, 2017
·Updated
In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.
Affected Software
3 affected components
Irssi irssi<=1.0.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Patch Available
Event History
Jun 7, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9468?
CVE-2017-9468 has a medium severity level as it can cause application crashes.
2
How do I fix CVE-2017-9468?
To fix CVE-2017-9468, upgrade Irssi to version 1.0.3 or later.
3
Which versions of Irssi are affected by CVE-2017-9468?
Irssi versions prior to 1.0.3 are affected by CVE-2017-9468.
4
Can CVE-2017-9468 lead to remote code execution?
CVE-2017-9468 does not lead to remote code execution, but it could allow a denial of service condition.
5
Is CVE-2017-9468 specific to any operating system?
CVE-2017-9468 affects Irssi on various operating systems, including Debian Linux versions 8.0 and 9.0.