logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "170773509928154751479710606776237040763", "237308360498408220310260530371249725246", "10393286597988245061607581881250570256", "142633329609863538958440850511094736890", "59179709387307661710312013769750997199", "38870636279499039213458583927901942414", "12014968714811209323881381971033427845", "171360617087082458170711858982298322195", "54389341007443020156669760539280105183", "333804995871122281858402152413478048122", "100576315683443650551677216263893387208", "294818707222886027522663250928605470711", "307818560861228328586683512412050312656", "103199274744530277918538084863188522900", "119878620889294396324412496275722282965", "136348436901529359361827113246458330096", "27380423915514142819662237032468771453", "314957055069730641521329396920877734870", "124396455555445469758548740141750189780", "79824535120446192235353060782403030413", "127660784454887595572668568782211532832", "155576718715398878875537603315037499093", "215386899310165895157852949370985738041", "52533862405131551259284877327101670671", "259351158318020861156815277739985425670", "289151465185287331232746447085643265811", "61661078011562799915094550259624405824", "281610449807137159598750948519188446337", "53093743963042786944162311225797223936", "301293759848643900244115674967542385536", "338891881211026587900954235364767369769", "135870506344505448895049157251985337454", "112200652825481983768859271530675882791", "238971132729297460865920521673271058894", "270978184716875515782924507135553886320", "130513285988024201014924219642661699156", "120866271656626384049386293042761727502", "145704897024969338685708046801466434264", "256596882769971908197749701284157609190", "160162072844295790929345564488917656240", "37625326552263767808580077069052895726", "201657696754097016665723773849689755349", "92965460573344646335663159280352794353", "272909398761115434999926300507079305013", "200774378162292862980561484899567860619", "339143388981428787803074307723164760098", "52204715842098260249273175341822894713", "65569329782503795407563160786586060618", "155613931555744231585279332488657101577", "332899048743490956799442511428771578618", "154988045710622114713717878060835266287", "156788134656017729924282146574686165717", "333516270655194357653140906477457138908", "62534946277781260572384753165349144498", "192647027075265191129904041353861687277", "247296518109704560182093575457504004921", "219976687675206257339274716733941383114", "41164156565970040101944195052764973816", "271269837606409226327446998218597208470", "322750209629461202577052129357631447603", "319300271870536544656061292061760621529", "241721554091473910159699125999055406882", "294991960825917142046537478653797107109", "299910582308124548764107396599096756883", "163275181162821078816768700647007279537", "73244506414227479416911864183505911323", "324465517084701743203825471510126000804", "281013914468663009277169711617173193092" ] }, "signature_type": "Line", "source": "https://github.com/weechat/weechat/commit/f105c6f0b56fb5687b2d2aedf37cb1d1b434d556", "signature_version": "v1", "target": { "file": "src/plugins/logger/logger.c" }, "deprecated": false, "id": "CVE-2017-14727-82560d30" }, { "digest": { "function_hash": "299004748674351366492445718559814171411", "length": 1478.0 }, "signature_type": "Function", "source": "https://github.com/weechat/weechat/commit/f105c6f0b56fb5687b2d2aedf37cb1d1b434d556", "signature_version": "v1", "target": { "file": "src/plugins/logger/logger.c", "function": "logger_get_mask_expanded" }, "deprecated": false, "id": "CVE-2017-14727-be65734a" } ] }