CVE-2012-5534: Input Validation
Published Dec 3, 2012
·Updated
The hookprocess function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."
Affected Software
11 affected components
Flashtux Weechat=0.3.0
Flashtux Weechat=0.3.1
Flashtux Weechat=0.3.1.1
Flashtux Weechat=0.3.2
Flashtux Weechat=0.3.3
Flashtux Weechat=0.3.4
Flashtux Weechat=0.3.6
Flashtux Weechat=0.3.7
Flashtux Weechat=0.3.8
Flashtux Weechat=0.3.9
Flashtux Weechat=0.3.9.1
Remediation
Patch Available
Event History
Dec 3, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5534?
CVE-2012-5534 is considered a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2012-5534?
To fix CVE-2012-5534, update WeeChat to version 0.3.9.2 or later to ensure the vulnerability is patched.
3
What versions of WeeChat are affected by CVE-2012-5534?
CVE-2012-5534 affects WeeChat versions 0.3.0 through 0.3.9.1.
4
Can CVE-2012-5534 lead to a complete system compromise?
Yes, CVE-2012-5534 can potentially allow attackers to execute arbitrary commands, which may lead to a complete system compromise.
5
Is there a workaround for CVE-2012-5534?
A practical workaround for CVE-2012-5534 is to disable or restrict the use of plugins in the affected versions of WeeChat.