Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Flashcode

#17883of 53,608
15Total CVSS
Vulnerabilities · 2
High
2
PT-2012-6007
7.5
2012-12-03
Weechat · Weechat · CVE-2012-5534
**Name of the Vulnerable Software and Affected Versions** WeeChat versions 0.3.0 through 0.3.9.1 **Description** The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to shell expansion, by exploiting the `hook process` function in the plugin API. **Recommendations** For WeeChat versions 0.3.0 through 0.3.9.1, consider disabling the `hook process` function until a patch is available to prevent exploitation. Restrict access to plugins that utilize the `hook process` function to minimize the risk of arbitrary command execution. Avoid using shell metacharacters in commands from plugins to reduce the risk of shell expansion issues.
PT-2012-6152
7.5
2012-11-19
Weechat · Weechat · CVE-2012-5854
**Name of the Vulnerable Software and Affected Versions** WeeChat versions 0.3.6 through 0.3.9 **Description** The issue is related to a heap-based buffer overflow that can be triggered by remote attackers sending crafted IRC colors that are not properly decoded, potentially leading to a denial of service or the execution of arbitrary code. **Recommendations** For WeeChat versions 0.3.6 through 0.3.9, update to a version that contains a fix for this issue.