WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade weechat | Oct 1, 2024 | Sep 5, 2021 |
| Debian | — | Upgrade weechat | Nov 29, 2021 | Sep 5, 2021 |
| Suse | — | Upgrade weechat-perlUpgrade weechat-rubyUpgrade weechat-luaUpgrade weechat-tclUpgrade weechat-spellUpgrade weechat-develUpgrade weechatUpgrade weechat-langUpgrade weechat-python | Mar 22, 2022 | Sep 5, 2021 |
| Ubuntu | — | Upgrade weechat-lua (Ubuntu Pro)Upgrade weechat-ruby (Ubuntu Pro)Upgrade weechat-headless (Ubuntu Pro)Upgrade weechat (Ubuntu Pro)Upgrade weechat-perl (Ubuntu Pro)Upgrade weechat-guile (Ubuntu Pro)Upgrade weechat-tcl (Ubuntu Pro)Upgrade weechat-python (Ubuntu Pro)Upgrade weechat-php (Ubuntu Pro)Upgrade weechat-curses (Ubuntu Pro)Upgrade weechat-core (Ubuntu Pro)Upgrade weechat-plugins (Ubuntu Pro) | Mar 22, 2023 | Sep 5, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub