CVE-2017-9468: Debian Linux

High severity, CVSS 7.5. EPSS: 3.7% chance of exploitation in the next 30 days.

In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Irssi Irssi: up to and including 1.0.2

Published 2017-06-07. Last modified 2026-06-17.