CVE-2018-9240: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur.
Affected products
- Canonical Ubuntu Linux: version 16.04 only
- Debian Debian Linux: version 8.0 only
- Ncmpc Project Ncmpc: up to and including 0.29
Published 2018-04-03. Last modified 2026-06-17.