WeeChat Color Decoding Heap Buffer Overflow Vulnerability
17 Dec. 2012
Summary
WeeChat is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Credit:
The information has been provided by Sebastien Helleu.
Vulnerable Systems:
* WeeChat versions 0.3.6 and prior
Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.