CVE-2018-7052: Null Pointer Dereference
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL pointer dereference would occur.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/irssito a version that resolves this vulnerability.Fixed in 1.2.3-1Fixed in 1.4.3-2Fixed in 1.4.5-1 - Upgrade
Upgrade
irssito a version that resolves this vulnerability.Fixed in 1.0.7 - Upgrade
Upgrade
irssito a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7052?
CVE-2018-7052 is classified as a moderate severity vulnerability due to its potential to crash the application.
How do I fix CVE-2018-7052?
To fix CVE-2018-7052, upgrade Irssi to versions 1.2.3-1 or higher, or 1.4.3-2 or higher.
Which versions of Irssi are affected by CVE-2018-7052?
Irssi versions before 1.0.7 and all 1.1.x versions before 1.1.1 are affected by CVE-2018-7052.
What systems are impacted by CVE-2018-7052?
CVE-2018-7052 impacts systems running affected versions of Irssi, including Debian and various Ubuntu versions.
Can CVE-2018-7052 cause data loss?
While CVE-2018-7052 may lead to application crashes, it does not directly cause data loss.