PT-2012-6007 · Weechat+1 · Weechat+1

Flashcode

+1

·

Published

2012-12-03

·

Updated

2014-02-07

·

CVE-2012-5534

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WeeChat versions 0.3.0 through 0.3.9.1
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to shell expansion, by exploiting the hook process function in the plugin API.
Recommendations For WeeChat versions 0.3.0 through 0.3.9.1, consider disabling the hook process function until a patch is available to prevent exploitation. Restrict access to plugins that utilize the hook process function to minimize the risk of arbitrary command execution. Avoid using shell metacharacters in commands from plugins to reduce the risk of shell expansion issues.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5534
DSA-2598-1
OPENSUSE-SU-2013_0150-1

Affected Products

Suse
Weechat