CVE-2009-0661: Input Validation
Published Mar 19, 2009
·Updated
Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.
Affected Software
1 affected component
Flashtux Weechat=0.2.6
Remediation
Patch Available
Patch Available
Event History
Mar 19, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:30 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0661?
CVE-2009-0661 has a severity level that can lead to denial of service due to application crashes, making it a notable vulnerability.
2
How do I fix CVE-2009-0661?
To fix CVE-2009-0661, you should upgrade to a newer version of WeeChat that addresses this vulnerability.
3
What types of attacks does CVE-2009-0661 facilitate?
CVE-2009-0661 facilitates remote denial of service attacks via crafted IRC PRIVMSG commands.
4
What affected versions are impacted by CVE-2009-0661?
The affected version by CVE-2009-0661 is WeeChat 0.2.6.
5
Can CVE-2009-0661 be exploited from a local network?
Yes, CVE-2009-0661 can be exploited from a local network if an attacker can send crafted IRC PRIVMSG commands to the vulnerable WeeChat client.