In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.debian.org/security/2017/dsa-3885 | third party advisory vendor advisory |
http://openwall.com/lists/oss-security/2017/06/06/4 | mailing list third party advisory patch |
https://irssi.org/security/irssi_sa_2017_06.txt | patch vendor advisory |
http://www.securityfocus.com/bid/99015 | vdb entry third party advisory |
http://www.securitytracker.com/id/1038621 | vdb entry third party advisory |