A NULL pointer dereference was found in Irssi in complete_from_nicklist function of chat-completion.c file, when an "empty" nick joins a channel. A remote attacker, who can control an IRC server, could crash IRC clients by leveraging this vulnerability. Upstream patch: https://github.com/irssi/irssi/commit/36564717c9f701e3a339da362ab46d220d27e0c1 References: https://irssi.org/security/irssi_sa_2018_02.txt
Created irssi tracking bugs for this issue: Affects: fedora-all [bug 1546315]