WeeChat 'hook_process()' Function Remote Shell Command Injection Vulnerability
BID:56584
Info
WeeChat 'hook_process()' Function Remote Shell Command Injection Vulnerability
| Bugtraq ID: | 56584 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5534 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2012 12:00AM |
| Updated: | Apr 13 2015 09:30PM |
| Credit: | Sebastien Helleu |
| Vulnerable: |
SuSE openSUSE 11.4 Gentoo Linux FlashTux WeeChat 0.3.4 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
WeeChat 'hook_process()' Function Remote Shell Command Injection Vulnerability
WeeChat is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the application.
Versions prior to WeeChat 0.3.9.2 are vulnerable.
WeeChat is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the application.
Versions prior to WeeChat 0.3.9.2 are vulnerable.
Exploit / POC
WeeChat 'hook_process()' Function Remote Shell Command Injection Vulnerability
To exploit this issue, attackers can use a browser or readily available network utilities.
To exploit this issue, attackers can use a browser or readily available network utilities.
Solution / Fix
WeeChat 'hook_process()' Function Remote Shell Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
-
Mandriva weechat-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-aspell-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-charset-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-devel-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-lua-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-perl-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-python-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-ruby-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva weechat-tcl-0.3.6-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
WeeChat 'hook_process()' Function Remote Shell Command Injection Vulnerability
References:
References:
- WeeChat Homepage (FlashTux)