PT-2012-6007 · Weechat+1 · Weechat+1

Flashcode

+1

·

Publicado

2012-12-03

·

Atualizado

2014-02-07

·

CVE-2012-5534

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WeeChat versions 0.3.0 through 0.3.9.1
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to shell expansion, by exploiting the hook process function in the plugin API.
Recommendations For WeeChat versions 0.3.0 through 0.3.9.1, consider disabling the hook process function until a patch is available to prevent exploitation. Restrict access to plugins that utilize the hook process function to minimize the risk of arbitrary command execution. Avoid using shell metacharacters in commands from plugins to reduce the risk of shell expansion issues.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5534
DSA-2598-1
OPENSUSE-SU-2013_0150-1

Produtos afetados

Suse
Weechat