CVE-2012-5534
EPSS 4.4%
Description
The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."
How to fix CVE-2012-5534
To remediate CVE-2012-5534, upgrade the affected package to a fixed version below.
- Debian/weechat—upgrade to 0.3.9.2-1 or later
Is CVE-2012-5534 being exploited?
Low — EPSS is 4.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.3.9.2-1