ALT-PU-2022-1588-1
Closed vulnerabilities
Published: 2021-09-05
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-40516
WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- https://github.com/weechat/weechat/commit/8b1331f98de1714bae15a9ca2e2b393ba49d735b
- https://github.com/weechat/weechat/commit/8b1331f98de1714bae15a9ca2e2b393ba49d735b
- [debian-lts-announce] 20210930 [SECURITY] [DLA 2770-1] weechat security update
- [debian-lts-announce] 20210930 [SECURITY] [DLA 2770-1] weechat security update
- https://weechat.org/doc/security/
- https://weechat.org/doc/security/