In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://www.debian.org/security/2017/dsa-4016 | third party advisory vendor advisory |
https://irssi.org/security/irssi_sa_2017_10.txt | patch vendor advisory mitigation |
http://openwall.com/lists/oss-security/2017/10/22/4 | mailing list patch mitigation third party advisory |