Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade weechat | Jul 30, 2024 | Nov 19, 2012 |
| Freebsd | — | Upgrade weechat-develUpgrade weechat | Dec 10, 2025 | Nov 10, 2012 |
| Gentoo Linux | — | Upgrade net-irc/weechat. | Oct 30, 2017 | Nov 19, 2012 |
| Suse | — | Upgrade weechatUpgrade weechat-tcl-debuginfoUpgrade weechat-tclUpgrade weechat-langUpgrade weechat-aspellUpgrade weechat-debugsourceUpgrade weechat-rubyUpgrade weechat-ruby-debuginfoUpgrade weechat-perlUpgrade weechat-python-debuginfoUpgrade weechat-guileUpgrade weechat-lua-debuginfoUpgrade weechat-pythonUpgrade weechat-luaUpgrade weechat-perl-debuginfoUpgrade weechat-develUpgrade weechat-aspell-debuginfoUpgrade weechat-debuginfo | Feb 17, 2015 | Nov 19, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub