CVE-2024-46613: Integer Overflow
Published Nov 10, 2024
·Updated
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects stringfreesplitshared , stringfreesplit, stringfreesplitcommand, and stringfreesplittags.
Affected Software
1 affected component
WeeChat WeeChat>=0.1.6<4.4.2
Event History
Nov 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-46613?
CVE-2024-46613 is classified with a high severity due to its potential to cause integer and buffer overflows.
2
How do I fix CVE-2024-46613?
To fix CVE-2024-46613, upgrade WeeChat to version 4.4.2 or later.
3
What components are affected by CVE-2024-46613?
CVE-2024-46613 affects functions in core/core-string.c related to string handling and list management.
4
Is there a workaround for CVE-2024-46613?
There is no known workaround for CVE-2024-46613, and upgrading is the recommended mitigation.
5
When was CVE-2024-46613 reported?
CVE-2024-46613 was reported for versions of WeeChat prior to 4.4.2.