PT-2020-7168 · Xchat-Wdk+1 · Xchat-Wdk+1
Jan Lieskovsky
·
Published
2020-02-21
·
Updated
2020-03-05
·
CVE-2012-0828
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xchat-WDK versions prior to 1499-4
xchat version 2.8.6
Description
A heap-based buffer overflow could allow remote attackers to cause a denial of service or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).
Recommendations
For Xchat-WDK versions prior to 1499-4, update to version 1499-4 or later to resolve the issue.
For xchat version 2.8.6, consider disabling the handling of UTF-8 lines from servers until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xchat-Wdk
Xchat