An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buffer overflow and possibly a crash can happen when a new mode is set for a nick.
{ "vanir_signatures": [ { "target": { "file": "src/plugins/irc/irc-server.c" }, "signature_type": "Line", "source": "https://github.com/weechat/weechat/commit/40ccacb4330a64802b1f1e28ed9a6b6d3ca9197f", "deprecated": false, "id": "CVE-2020-9760-24b17d3c", "digest": { "threshold": 0.9, "line_hashes": [ "325596194213706182479652272081936598340", "132268216224256037571839750429924175280", "44497950053967307772718137244273875544", "132550677232131315184311444001429665351", "97418110254259639727718916227023582353", "149303952922933676077113852457245993771", "129402597196439469058390957584289549233", "108587633537507210242609878158511307392", "111708766549982062342636204382193101079", "167118086744474657822052685044811994853" ] }, "signature_version": "v1" }, { "target": { "file": "src/plugins/irc/irc-nick.h" }, "signature_type": "Line", "source": "https://github.com/weechat/weechat/commit/40ccacb4330a64802b1f1e28ed9a6b6d3ca9197f", "deprecated": false, "id": "CVE-2020-9760-6054fd6a", "digest": { "threshold": 0.9, "line_hashes": [ "213054129778902522372905892267968144680", "131097610739893464754850419081481526954", "228471673978473928265094791230654823703", "197161856197992666943380620234508962100" ] }, "signature_version": "v1" }, { "target": { "function": "irc_server_set_prefix_modes_chars", "file": "src/plugins/irc/irc-server.c" }, "signature_type": "Function", "source": "https://github.com/weechat/weechat/commit/40ccacb4330a64802b1f1e28ed9a6b6d3ca9197f", "deprecated": false, "id": "CVE-2020-9760-a185fca6", "digest": { "function_hash": "128916233876534572922588486440859965445", "length": 863.0 }, "signature_version": "v1" } ] }