CVE-2012-0828: Gnome Gtk

Critical severity, CVSS 9.8. EPSS: 4.3% chance of exploitation in the next 30 days.

Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).

Affected products

  • Gnome Gtk: version 2.10.4 only; version 2.14.7 only; version 2.18.9 only; version 2.24.7 only
  • Xchat Xchat: before 2.8.6 (fixed in 2.8.6)
  • Xchat-Wdk Xchat-Wdk: before 1499-4 (fixed in 1499-4)

Published 2020-02-21. Last modified 2026-06-16.