Vulnerability Description
logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weechat | Logger | - |
| Weechat | Weechat | 0.3.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101003Third Party AdvisoryVDB Entry
- https://github.com/weechat/weechat/commit/f105c6f0b56fb5687b2d2aedf37cb1d1b434d5PatchThird Party Advisory
- https://weechat.org/download/security/Vendor Advisory
- https://weechat.org/news/98/20170923-Version-1.9.1-security-release/Release NotesVendor Advisory
- http://www.securityfocus.com/bid/101003Third Party AdvisoryVDB Entry
- https://github.com/weechat/weechat/commit/f105c6f0b56fb5687b2d2aedf37cb1d1b434d5PatchThird Party Advisory
- https://weechat.org/download/security/Vendor Advisory
- https://weechat.org/news/98/20170923-Version-1.9.1-security-release/Release NotesVendor Advisory
FAQ
What is CVE-2017-14727?
CVE-2017-14727 is a vulnerability with a CVSS score of 7.5 (HIGH). logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
How severe is CVE-2017-14727?
CVE-2017-14727 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14727?
Check the references section above for vendor advisories and patch information. Affected products include: Weechat Logger, Weechat Weechat.