CVE-2017-10965NULL Pointer Dereference in Irssi

Severity
9.8CRITICALNVD
EPSS
1.5%
top 19.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 7
Latest updateMay 17

Description

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/irssi< irssi 1.0.4-1 (bookworm)
Debianirssi/irssi< 1.0.4-1+3
Ubuntuirssi/irssi< 0.8.15-5ubuntu3.3+1
NVDirssi/irssi1.0.3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-54h6-8x6r-vr9v: An issue was discovered in Irssi before 12022-05-17
OSV
irssi vulnerabilities2017-10-26
OSV
CVE-2017-10965: An issue was discovered in Irssi before 12017-07-07

📋Vendor Advisories

3
Ubuntu
Irssi vulnerabilities2017-10-26
Red Hat
irssi: NULL pointer dereference when receiving messages with invalid time stamps2017-07-05
Debian
CVE-2017-10965: irssi - An issue was discovered in Irssi before 1.0.4. When receiving messages with inva...2017

💬Community

2
HackerOne
CVE-2017-10965: Null pointer dereference in Irssi <1.0.42019-10-04
Bugzilla
CVE-2017-10965 irssi: NULL pointer dereference when receiving messages with invalid time stamps2017-07-20