An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buffer overflow and possibly a crash can happen when a new mode is set for a nick.
[
{
"signature_version": "v1",
"source": "https://github.com/weechat/weechat/commit/40ccacb4330a64802b1f1e28ed9a6b6d3ca9197f",
"signature_type": "Line",
"target": {
"file": "src/plugins/irc/irc-server.c"
},
"deprecated": false,
"id": "CVE-2020-9760-24b17d3c",
"digest": {
"line_hashes": [
"325596194213706182479652272081936598340",
"132268216224256037571839750429924175280",
"44497950053967307772718137244273875544",
"132550677232131315184311444001429665351",
"97418110254259639727718916227023582353",
"149303952922933676077113852457245993771",
"129402597196439469058390957584289549233",
"108587633537507210242609878158511307392",
"111708766549982062342636204382193101079",
"167118086744474657822052685044811994853"
],
"threshold": 0.9
}
},
{
"signature_version": "v1",
"source": "https://github.com/weechat/weechat/commit/40ccacb4330a64802b1f1e28ed9a6b6d3ca9197f",
"signature_type": "Line",
"target": {
"file": "src/plugins/irc/irc-nick.h"
},
"deprecated": false,
"id": "CVE-2020-9760-6054fd6a",
"digest": {
"line_hashes": [
"213054129778902522372905892267968144680",
"131097610739893464754850419081481526954",
"228471673978473928265094791230654823703",
"197161856197992666943380620234508962100"
],
"threshold": 0.9
}
},
{
"signature_version": "v1",
"source": "https://github.com/weechat/weechat/commit/40ccacb4330a64802b1f1e28ed9a6b6d3ca9197f",
"signature_type": "Function",
"target": {
"function": "irc_server_set_prefix_modes_chars",
"file": "src/plugins/irc/irc-server.c"
},
"deprecated": false,
"id": "CVE-2020-9760-a185fca6",
"digest": {
"function_hash": "128916233876534572922588486440859965445",
"length": 863.0
}
}
]