CVE-2009-0661Improper Input Validation in Weechat

Severity
5.0MEDIUMNVD
EPSS
2.0%
top 16.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 2

Description

Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/weechat< weechat 0.2.6.1-1 (bookworm)
Debianweechat/weechat< 0.2.6.1-1+3
NVDflashtux/weechat0.2.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x574-mhvf-59h5: Wee Enhanced Environment for Chat (WeeChat) 02022-05-02
OSV
CVE-2009-0661: Wee Enhanced Environment for Chat (WeeChat) 02009-03-19

📋Vendor Advisories

2
Red Hat
WeeChat: DoS (crash) when receiving special characters in IRC messages2009-03-14
Debian
CVE-2009-0661: weechat - Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cau...2009

💬Community

1
Bugzilla
CVE-2009-0661 WeeChat: DoS (crash) when receiving special characters in IRC messages2009-03-17