WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes function during quote removal, with a buffer overflow.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-919-1 weechat security update
Debian DSA Debian DSA DSA-3836-1 weechat security update
EUVD EUVD EUVD-2017-17036 WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes function during quote removal, with a buffer overflow.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T16:27:21.389Z

Reserved: 2017-04-23T00:00:00

Link: CVE-2017-8073

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-04-23T15:59:00.200

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-8073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.