Candidate: CVE-2012-5854 PublicDate: 2012-11-19 12:10:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5854 http://www.openwall.com/lists/oss-security/2012/11/12 Description: Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=693026 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_weechat: upstream_weechat: released (0.3.9.1-1) hardy_weechat: ignored (reached end-of-life) lucid_weechat: ignored (reached end-of-life) oneiric_weechat: ignored (reached end-of-life) precise_weechat: ignored (reached end-of-life) precise/esm_weechat: DNE (precise was needed) quantal_weechat: ignored (reached end-of-life) raring_weechat: not-affected (0.3.9.1-1) saucy_weechat: not-affected (0.3.9.1-1) trusty_weechat: not-affected (0.3.9.1-1) trusty/esm_weechat: DNE (trusty was not-affected [0.3.9.1-1]) utopic_weechat: not-affected (0.3.9.1-1) vivid_weechat: not-affected (0.3.9.1-1) vivid/stable-phone-overlay_weechat: DNE vivid/ubuntu-core_weechat: DNE wily_weechat: not-affected (0.3.9.1-1) xenial_weechat: not-affected (0.3.9.1-1) yakkety_weechat: not-affected (0.3.9.1-1) zesty_weechat: not-affected (0.3.9.1-1) devel_weechat: not-affected (0.3.9.1-1)