WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade weechat | Oct 1, 2024 | Sep 5, 2021 |
| Debian | — | Upgrade weechat | Nov 29, 2021 | Sep 5, 2021 |
| Suse | — | Upgrade weechat-tclUpgrade weechat-spellUpgrade weechatUpgrade weechat-langUpgrade weechat-develUpgrade weechat-pythonUpgrade weechat-rubyUpgrade weechat-luaUpgrade weechat-perl | Mar 22, 2022 | Sep 5, 2021 |
| Ubuntu | — | Upgrade weechat-php (Ubuntu Pro)Upgrade weechat-python (Ubuntu Pro)Upgrade weechat-plugins (Ubuntu Pro)Upgrade weechat-core (Ubuntu Pro)Upgrade weechat-curses (Ubuntu Pro)Upgrade weechat-headless (Ubuntu Pro)Upgrade weechat-guile (Ubuntu Pro)Upgrade weechat-perl (Ubuntu Pro)Upgrade weechat-lua (Ubuntu Pro)Upgrade weechat-ruby (Ubuntu Pro)Upgrade weechat (Ubuntu Pro)Upgrade weechat-tcl (Ubuntu Pro) | Mar 22, 2023 | Sep 5, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub