CRITICAL
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode)
Published Feb 12, 2020
9.8
CRITICALCVSS 3.1
EPSS 3.68%
Description
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
Affected products
No data.
Configuration 2
OR
- 30
- 31
- 32
Configuration 3
OR
- 15.0
- 15.0
- 15.1
Configuration 4
OR
- 8.0
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00032.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://github.com/weechat/weechat/commit/6f4f147d8e86adf9ad34a8ffd7e7f1f23a7e74da x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00031.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/09/msg00018.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ASRTCQFFDAAK347URWNDH6NSED2BGNY/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER23GT23US5JXDLUZAMGMWXKZ74MI4S2/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M3LAJTLI3LWZRNCFYJ7PCBBTHUMCCBHH/ vendor-advisoryx_refsource_FEDORA
- https://security.gentoo.org/glsa/202003-51 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://weechat.org/doc/security/ x_refsource_MISCVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 12, 2020
Updated Aug 4, 2024
Reserved Feb 12, 2020
Link CVE-2020-8955
CISA Vulnrichment
Updated n/a