CVE-2020-9759Download of Code Without Integrity Check in Weechat

Severity
7.8HIGHNVD
OSV7.5
EPSS
0.2%
top 63.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 23
Latest updateMay 24

Description

A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

debiandebian/weechat< weechat 2.7.1-1 (bookworm)
Debianweechat/weechat< 2.7.1-1+3
Ubuntuweechat/weechat< 1.4-2ubuntu0.1+esm1+2

🔴Vulnerability Details

3
GHSA
GHSA-j24f-gw9v-x4vp: An issue was discovered in WeeChat before 22022-05-24
OSV
weechat vulnerabilities2022-02-04
OSV
CVE-2020-9759: A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files2020-03-23

📋Vendor Advisories

2
Ubuntu
WeeChat vulnerabilities2022-02-04
Debian
CVE-2020-9759: weechat - A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to e...2020

💬Community

5
Bugzilla
CVE-2020-9759 weechat: malformed message 352 (who) can cause a NULL pointer dereference in the callback function which could result in a crash. [epel-7]2020-03-26
Bugzilla
CVE-2020-9759 weechat: malformed message 352 (who) can cause a NULL pointer dereference in the callback function which could result in a crash. [fedora-all]2020-03-26
Bugzilla
CVE-2020-9759 weechat: malformed message 352 (who) can cause a NULL pointer dereference in the callback function which could result in a crash. [epel-6]2020-03-26
Bugzilla
CVE-2020-9759 weechat: malformed message 352 (who) can cause a NULL pointer dereference in the callback function which could result in a crash.2020-03-26
Bugzilla
CVE-2020-9759 weechat: malformed message 352 (who) can cause a NULL pointer dereference in the callback function which could result in a crash. [epel-6]2020-03-26