CVE-2012-5854
EPSS 5.5%
Description
Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.
How to fix CVE-2012-5854
To remediate CVE-2012-5854, upgrade the affected package to a fixed version below.
- Debian/weechat—upgrade to 0.3.9.1-1 or later
Is CVE-2012-5854 being exploited?
Moderate — EPSS is 5.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.3.9.1-1