5

CVE-2009-0661

Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FlashtuxWeechat Version0.2.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.11% 0.861
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=519940
http://osvdb.org/52763
http://savannah.nongnu.org/bugs/index.php?25862
http://secunia.com/advisories/34304
Vendor Advisory
http://secunia.com/advisories/34328
Vendor Advisory
http://weechat.flashtux.org/
Vendor Advisory
http://www.debian.org/security/2009/dsa-1744
http://www.openwall.com/lists/oss-security/2009/03/17/8
http://www.securityfocus.com/bid/34148
Patch
http://www.vupen.com/english/advisories/2009/0758
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49295