CVE-2017-10965
published 2017-07-07CVE-2017-10965: An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
PriorityP337critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.44%
87.6th percentile
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | irssi | < irssi 1.0.4-1 (bookworm) | irssi 1.0.4-1 (bookworm) |
| irssi | irssi | <= 1.0.3 | — |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 1.0.4-1 | 1.0.4-1 |
| irssi | irssi | >= 0 < 0.8.15-5ubuntu3.3 | 0.8.15-5ubuntu3.3 |
| irssi | irssi | >= 0 < 0.8.19-1ubuntu1.5 | 0.8.19-1ubuntu1.5 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Irssi vulnerabilities
vendor_ubuntu·2017-10-26·CVSS 9.8
CVE-2017-10965 [CRITICAL] Irssi vulnerabilities
Title: Irssi vulnerabilities
Summary: Several security issues were fixed in Irssi.
Brian Carpenter discovered that Irssi incorrectly handled messages with
invalid time stamps. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-10965)
Brian Carpenter discovered that Irssi incorrectly handled the internal nick
list. A malicious IRC server could use this issue to cause Irssi to crash,
resulting in a denial of service. (CVE-2017-10966)
Joseph Bisch discovered that Irssi incorrectly removed destroyed channels
from the query list. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-15227)
Hanno Böck discovered that Irssi incorrectly handled themes. If a user were
tricke
Red Hat
irssi: NULL pointer dereference when receiving messages with invalid time stamps
vendor_redhat·2017-07-05·CVSS 9.8
CVE-2017-10965 [CRITICAL] CWE-476 irssi: NULL pointer dereference when receiving messages with invalid time stamps
irssi: NULL pointer dereference when receiving messages with invalid time stamps
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
Package: irssi (Red Hat Enterprise Linux 6) - Will not fix
Package: irssi (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-10965: irssi - An issue was discovered in Irssi before 1.0.4. When receiving messages with inva...
vendor_debian·2017·CVSS 9.8
CVE-2017-10965 [CRITICAL] CVE-2017-10965: irssi - An issue was discovered in Irssi before 1.0.4. When receiving messages with inva...
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
Scope: local
bookworm: resolved (fixed in 1.0.4-1)
bullseye: resolved (fixed in 1.0.4-1)
forky: resolved (fixed in 1.0.4-1)
sid: resolved (fixed in 1.0.4-1)
trixie: resolved (fixed in 1.0.4-1)
GHSA
GHSA-54h6-8x6r-vr9v: An issue was discovered in Irssi before 1
ghsa_unreviewed·2022-05-17
CVE-2017-10965 [CRITICAL] CWE-476 GHSA-54h6-8x6r-vr9v: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
OSV
irssi vulnerabilities
osv·2017-10-26·CVSS 9.8
CVE-2017-10965 [CRITICAL] irssi vulnerabilities
irssi vulnerabilities
Brian Carpenter discovered that Irssi incorrectly handled messages with
invalid time stamps. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-10965)
Brian Carpenter discovered that Irssi incorrectly handled the internal nick
list. A malicious IRC server could use this issue to cause Irssi to crash,
resulting in a denial of service. (CVE-2017-10966)
Joseph Bisch discovered that Irssi incorrectly removed destroyed channels
from the query list. A malicious IRC server could use this issue to cause
Irssi to crash, resulting in a denial of service. (CVE-2017-15227)
Hanno Böck discovered that Irssi incorrectly handled themes. If a user were
tricked into using a malicious theme, a attacker could use this issu
OSV
CVE-2017-10965: An issue was discovered in Irssi before 1
osv·2017-07-07·CVSS 9.8
CVE-2017-10965 [CRITICAL] CVE-2017-10965: An issue was discovered in Irssi before 1
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2017-10965: Null pointer dereference in Irssi <1.0.4
hackerone·2019-10-04·CVSS 9.8
CVE-2017-10965 [CRITICAL] CVE-2017-10965: Null pointer dereference in Irssi <1.0.4
CVE-2017-10965: Null pointer dereference in Irssi <1.0.4
34 days after reading https://irssi.org/2017/05/12/fuzzing-irssi/, I was finally able to trigger a null pointer dereference in irssi 1.0.2.
Timeline:
Report to vendor: 15 June 2017
Acknowledge by vendor: 15 June 2017
Fixed by vendor: 7 July 2017
Advisory:
http://seclists.org/oss-sec/2017/q3/80
Patch:
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206
```
./irssi < test000
CAP LS
NICK root
USER root root /dev/stdin :root
ASAN:DEADLYSIGNAL
==23308==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7f4505521e56 bp 0x7fff0bf30d90 sp 0x7fff0bf30518 T0)
==23308==The signal is caused by a READ memory access.
==23308==Hint: address points to the zero page.
#0 0x7f4505521e55 in strlen /build/glibc
Bugzilla
CVE-2017-10965 irssi: NULL pointer dereference when receiving messages with invalid time stamps
bugzilla·2017-07-20·CVSS 9.8
CVE-2017-10965 [CRITICAL] CVE-2017-10965 irssi: NULL pointer dereference when receiving messages with invalid time stamps
CVE-2017-10965 irssi: NULL pointer dereference when receiving messages with invalid time stamps
An issue was discovered in Irssi. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
Upstream patch:
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291
External References:
https://irssi.org/security/irssi_sa_2017_07.txt
Discussion:
Lowering severity based on the fact that the specially crafted message has to be sent by the IRC server.
https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291https://irssi.org/security/irssi_sa_2017_07.txthttps://www.debian.org/security/2017/dsa-4016https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291https://irssi.org/security/irssi_sa_2017_07.txthttps://www.debian.org/security/2017/dsa-4016
2017-07-07
Published