5
CVSSv2

CVE-2017-9468

Published: 07/06/2017 Updated: 14/03/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Irssi prior to 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.

Vulnerable Product Search on Vulmon Subscribe to Product

irssi irssi

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Irssi could be made to crash if it received specially crafted network traffic ...
Debian Bug report logs - #879521 irssi: multiple vulnerabilities fixed in irssi 105 Package: src:irssi; Maintainer for src:irssi is Rhonda D'Vine <rhonda@debianorg>; Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Sun, 22 Oct 2017 15:27:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Foun ...
Debian Bug report logs - #864400 irssi: CVE-2017-9468 CVE-2017-9469 Package: src:irssi; Maintainer for src:irssi is Rhonda D'Vine <rhonda@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 8 Jun 2017 05:33:02 UTC Severity: important Tags: patch, security, upstream Found in version irssi/0 ...
Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-9468 Joseph Bisch discovered that Irssi does not properly handle DCC messages without source nick/host A malicious IRC server can take advantage of this flaw ...
In Irssi before 103, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer Thus, remote IRC servers can cause a crash ...