Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.
| Software | From | Fixed in |
|---|---|---|
| flashtux / weechat | 0.3.9 | 0.3.9.x |
| flashtux / weechat | 0.3.7 | 0.3.7.x |
| flashtux / weechat | 0.3.8 | 0.3.8.x |
| flashtux / weechat | 0.3.6 | 0.3.6.x |