CVE-2018-9240

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
03/04/2018
Last modified:
20/01/2023

Description

ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ncmpc_project:ncmpc:*:*:*:*:*:*:*:* 0.29 (including)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*