CVE-2012-5854: Buffer Overflow
Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5854?
CVE-2012-5854 has a severity rating that indicates it allows for denial of service and potentially arbitrary code execution.
How do I fix CVE-2012-5854?
To fix CVE-2012-5854, upgrade WeeChat to the latest version that is not affected, specifically version 0.3.10 or higher.
What systems are affected by CVE-2012-5854?
CVE-2012-5854 affects WeeChat versions 0.3.6 through 0.3.9.
What type of attack does CVE-2012-5854 enable?
CVE-2012-5854 enables attacks that can result in application crashes or hangs and may allow remote code execution.
Is there a workaround for CVE-2012-5854?
While upgrading is the best solution, limiting the use of crafted IRC colors may serve as a temporary workaround for CVE-2012-5854.