Related Vulnerabilities: CVE-2017-14727  

It has been discovered that in logger.c in the logger plugin before weechat 1.9.1 the date/time conversion specifiers are expanded after replacing buffer local variables in name of log files. In some cases, this can lead to an error in function strftime and a crash caused by the use of an uninitialized buffer.

Severity Medium

Remote Yes

Type Denial of service

Description

It has been discovered that in logger.c in the logger plugin before weechat 1.9.1 the date/time conversion specifiers are expanded after replacing buffer local variables in name of log files. In some cases, this can lead to an error in function strftime and a crash caused by the use of an uninitialized buffer.

AVG-412 weechat 1.9-2 1.9.1-1 Medium Fixed

25 Sep 2017 ASA-201709-20 AVG-412 weechat Medium denial of service

https://weechat.org/download/security/
https://github.com/weechat/weechat/commit/e4cc90f4b43153dc1c6516c1f1aad2504faa5443