irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade weechat | Aug 22, 2024 | Feb 12, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 12, 2020 |
| Debian | — | Upgrade weechat | Mar 27, 2020 | Feb 12, 2020 |
| Freebsd | — | Upgrade weechat | Dec 10, 2025 | Feb 21, 2020 |
| Gentoo Linux | — | Upgrade net-irc/weechat. | Mar 27, 2020 | Feb 12, 2020 |
| Suse | — | Upgrade weechat-perlUpgrade weechat-guileUpgrade weechat-tclUpgrade weechat-develUpgrade weechat-pythonUpgrade weechat-luaUpgrade weechat-aspellUpgrade weechat-rubyUpgrade weechatUpgrade weechat-lang | Mar 3, 2020 | Feb 12, 2020 |
| Ubuntu | — | Upgrade weechat-headless (Ubuntu Pro)Upgrade weechat-guile (Ubuntu Pro)Upgrade weechat (Ubuntu Pro)Upgrade weechat-perl (Ubuntu Pro)Upgrade weechat-curses (Ubuntu Pro)Upgrade weechat-core (Ubuntu Pro)Upgrade weechat-php (Ubuntu Pro)Upgrade weechat-ruby (Ubuntu Pro)Upgrade weechat-lua (Ubuntu Pro)Upgrade weechat-tcl (Ubuntu Pro)Upgrade weechat-plugins (Ubuntu Pro)Upgrade weechat-python (Ubuntu Pro) | Mar 22, 2023 | Feb 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub