7.5
CVSSv2

CVE-2012-5854

Published: 19/11/2012 Updated: 07/02/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in WeeChat 0.3.6 up to and including 0.3.9 allows remote malicious users to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

flashtux weechat 0.3.6

flashtux weechat 0.3.7

flashtux weechat 0.3.8

flashtux weechat 0.3.9

Vendor Advisories

Debian Bug report logs - #693026 [CVE-2012-5854] weechat: Buffer overflow Package: weechat; Maintainer for weechat is Emmanuel Bouthenot <kolter@debianorg>; Source for weechat is src:weechat (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 12 Nov 2012 07:57:01 UTC Severity: grave Ta ...