5
CVSSv2

CVE-2009-0661

Published: 19/03/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote malicious users to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.

Vulnerable Product Search on Vulmon Subscribe to Product

flashtux weechat 0.2.6

Vendor Advisories

Sebastien Helleu discovered that an error in the handling of color codes in the weechat IRC client could cause an out-of-bounds read of an internal color array This can be used by an attacker to crash user clients via a crafted PRIVMSG command The weechat version in the oldstable distribution (etch) is not affected by this problem For the stable ...