CVE-2018-7050: Null Pointer Dereference
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/irssito a version that resolves this vulnerability.Fixed in 1.2.3-1Fixed in 1.4.3-2Fixed in 1.4.5-1 - Upgrade
Upgrade
Irssito a version that resolves this vulnerability.Fixed in 1.0.7 - Upgrade
Upgrade
Irssito a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7050?
CVE-2018-7050 has a medium severity level due to its potential to lead to application crashes.
How do I fix CVE-2018-7050?
To fix CVE-2018-7050, upgrade to Irssi version 1.0.7 or 1.1.1 and later.
Which versions of Irssi are affected by CVE-2018-7050?
CVE-2018-7050 affects Irssi versions prior to 1.0.7 and 1.1.x before 1.1.1.
What systems are vulnerable to CVE-2018-7050?
Debian versions prior to 9.0 and specific Ubuntu versions up to 17.10 are vulnerable to CVE-2018-7050.
What type of vulnerability is CVE-2018-7050?
CVE-2018-7050 is a NULL pointer dereference vulnerability that can occur under specific conditions.