WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects stringfreesplitshared , stringfreesplit, stringfreesplitcommand, and stringfreesplit_tags.
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.5.1-1", "binary_name": "weechat" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-core" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-core-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-curses" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-curses-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-dev" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-doc" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-guile" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-guile-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-headless" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-headless-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-lua" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-lua-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-perl" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-perl-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-php" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-php-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-plugins" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-plugins-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-python" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-python-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-ruby" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-ruby-dbgsym" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-tcl" }, { "binary_version": "4.5.1-1", "binary_name": "weechat-tcl-dbgsym" } ], "availability": "No subscription required" }