<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>20788</bug_id>
          
          <creation_ts>2009-07-15 15:59:28 +0400</creation_ts>
          <short_desc>CVE-2009-0661 WeeChat IRC Message Denial of Service</short_desc>
          <delta_ts>2011-01-29 19:45:57 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>weechat</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://secunia.com/advisories/34304/</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Alexey Gladkov">legion</assigned_to>
          <cc>grenka</cc>
    
    <cc>legion</cc>
    
    <cc>php-coder</cc>
    
    <cc>vvk</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>94697</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-07-15 15:59:28 +0400</bug_when>
    <thetext>A vulnerability has been reported in WeeChat, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error within the then handling of IRC messages containing certain color codes. This can be exploited to crash the application by sending specially crafted messages to a vulnerable client.

Fixed in version &gt;= 0.2.6.1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94699</commentid>
    <comment_count>1</comment_count>
    <who name="Konstantin Pavlov">thresh</who>
    <bug_when>2009-07-15 16:05:31 +0400</bug_when>
    <thetext>$ ssh git.alt acl sisyphus weechat show
weechat @nobody</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>117786</commentid>
    <comment_count>2</comment_count>
    <who name="Slava Semushin">php-coder</who>
    <bug_when>2011-01-29 19:45:57 +0300</bug_when>
    <thetext>В Сизифе 0.3.4</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>