CVE-2016-2233: Buffer Overflow
Published Jan 18, 2017
·Updated
Stack-based buffer overflow in the inboundcapls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.
Affected Software
1 affected component
Hexchat Project Hexchat=2.10.2
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-2233?
CVE-2016-2233 has a high severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2016-2233?
To fix CVE-2016-2233, update HexChat to version 2.11.0 or later.
3
What is the impact of CVE-2016-2233 on HexChat?
The impact of CVE-2016-2233 on HexChat includes crashes when processing malicious CAP LS messages from remote servers.
4
Which versions of HexChat are affected by CVE-2016-2233?
CVE-2016-2233 specifically affects HexChat version 2.10.2.
5
Is there a workaround for CVE-2016-2233?
There is no official workaround for CVE-2016-2233; upgrading to a patched version is recommended.