The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby-activesupportUpgrade weechat | Aug 30, 2017 | Dec 3, 2012 |
| Debian | — | Upgrade weechat | Jul 30, 2024 | Dec 3, 2012 |
| Gentoo Linux | — | Upgrade net-irc/weechat. | Oct 30, 2017 | Dec 3, 2012 |
| Suse | — | Upgrade weechat-tcl-debuginfoUpgrade weechat-tclUpgrade weechat-pythonUpgrade weechat-lua-debuginfoUpgrade weechat-debuginfoUpgrade weechat-langUpgrade weechat-guileUpgrade weechat-debugsourceUpgrade weechat-aspellUpgrade weechat-develUpgrade weechat-luaUpgrade weechatUpgrade weechat-python-debuginfoUpgrade weechat-aspell-debuginfoUpgrade weechat-perl-debuginfoUpgrade weechat-perlUpgrade weechat-ruby-debuginfoUpgrade weechat-ruby | Feb 17, 2015 | Dec 3, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub