ircmodechannel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:weechat:weechat:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0.3.8"
},
{
"last_affected": "2.7"
}
],
"vendor_product": "weechat:weechat"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "8.0"
},
{
"last_affected": "9.0"
}
],
"vendor_product": "debian:debian_linux"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "30"
},
{
"last_affected": "31"
},
{
"last_affected": "32"
}
],
"vendor_product": "fedoraproject:fedora"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*",
"cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.0-NA"
},
{
"last_affected": "15.0-sp1"
}
],
"vendor_product": "opensuse:backports_sle"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.1"
}
],
"vendor_product": "opensuse:leap"
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "2.7"
}
]
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-8955.json"
[
{
"target": {
"file": "src/plugins/irc/irc-mode.c",
"function": "irc_mode_channel_update"
},
"deprecated": false,
"digest": {
"function_hash": "223350524238790654043842164543245510326",
"length": 2502.0
},
"id": "CVE-2020-8955-1b8299ba",
"source": "https://github.com/weechat/weechat/commit/6f4f147d8e86adf9ad34a8ffd7e7f1f23a7e74da",
"signature_version": "v1",
"signature_type": "Function"
},
{
"target": {
"file": "src/plugins/irc/irc-mode.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"200879968070498314343440529766462460162",
"267790770994180775470654757621928752132",
"84311193978423127644732102481155587185",
"37738585302980977653187765980868653464",
"103144408093402382474082176671652325727",
"248047512738540522610242778759283707096",
"13726779807730142557510816354576803671",
"304711207680069284387163760563633707915",
"134091926362240965518819909662205922465",
"77567932931264461531056880510287982960",
"61653280659459939285653700726216165635",
"144127429652462822056848416788256299906",
"293177098233781010308844640392180242208",
"285905928978361185004924297576737108114"
],
"threshold": 0.9
},
"id": "CVE-2020-8955-afbcfe2f",
"source": "https://github.com/weechat/weechat/commit/6f4f147d8e86adf9ad34a8ffd7e7f1f23a7e74da",
"signature_version": "v1",
"signature_type": "Line"
}
]
"2026-05-30T17:07:39Z"