WeeChat: Multiple vulnerabilities — GLSA 202003-51

Multiple vulnerabilities have been found in WeeChat, the worst of which could allow remote attackers to cause a Denial of Service condition.

Affected packages

net-irc/weechat on all architectures
Affected versions < 2.7.1
Unaffected versions >= 2.7.1

Background

Wee Enhanced Environment for Chat (WeeChat) is a light and extensible console IRC client.

Description

Multiple vulnerabilities have been discovered in WeeChat. Please review the CVE identifiers referenced below for details.

Impact

A remote attacker, by sending a specially crafted IRC message, could possibly cause a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All WeeChat users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-irc/weechat-2.7.1"
 

References

Release date
March 25, 2020

Latest revision
March 25, 2020: 1

Severity
low

Exploitable
remote

Bugzilla entries