CVE-2020-9760: Buffer Overflow
An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buffer overflow and possibly a crash can happen when a new mode is set for a nick.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeeChatto a version that resolves this vulnerability.Fixed in 2.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9760?
CVE-2020-9760 is considered a critical vulnerability due to the potential for buffer overflow and crashes.
How do I fix CVE-2020-9760?
To fix CVE-2020-9760, update WeeChat to version 2.7.1 or later.
What versions of WeeChat are affected by CVE-2020-9760?
Versions of WeeChat from 0.3.4 to 2.7 are affected by CVE-2020-9760.
Which operating systems are impacted by CVE-2020-9760?
CVE-2020-9760 impacts WeeChat installations on Debian 8.0 and 9.0.
What types of attacks are possible due to CVE-2020-9760?
Exploitation of CVE-2020-9760 can lead to application crashes or potentially arbitrary code execution.