Version 3.4.1 is available, it fixes a security vulnerability: after changing gnutls options, the function used to validate certificates is not called any more, this can lead to a man-in-the-middle attack.
Upgrade is recommended for all users.
Sunday, March 13 2022
By Sébastien Helleu on Sunday, March 13 2022, 20:56 - core
Version 3.4.1 is available, it fixes a security vulnerability: after changing gnutls options, the function used to validate certificates is not called any more, this can lead to a man-in-the-middle attack.
Upgrade is recommended for all users.
Saturday, January 8 2022
By Sébastien Helleu on Saturday, January 8 2022, 16:40 - site
One thing is sure, we're not kidding with the security vulnerabilities, and our goal is to be completely transparent with the users about the issues as soon as they are public (ie with a new version, a fix/patch or at least a workaround available).
In this context, the security page has been redesigned from scratch, it is more user-friendly and a lot of new information has been added about each vulnerability.
The URL is unchanged: https://weechat.org/doc/security/.
Among the new information:
WSA-YEAR-ID
(YEAR
on 4 digits, and the ID
starts to 1 for the first vulnerability of this year, 2 for the second, etc.).Important: due to the way the CVSS vector, score and severity are computed, the severity level previously displayed has changed for some vulnerabilities and is now higher:
The page is now separated into two parts: the overview with only part of the info, and detail of each vulnerability below.
The overview shows synthesized data (click for full size):
Below this, the detail of each vulnerability is displayed, for example this detail about the latest security vulnerability, fixed in version 3.2.1 (September 2021):
For convenience, a list of vulnerabilities by WeeChat version is also available:
For the record and reference (especially old severities), the previous security page was:
Saturday, September 4 2021
By Sébastien Helleu on Saturday, September 4 2021, 15:42 - core
Version 3.2.1 is available, it fixes a security vulnerability: a malformed websocket frame received in relay plugin can cause a crash (CVE-2021-40516).
Upgrade is recommended for all users.
Thursday, February 20 2020
By Sébastien Helleu on Thursday, February 20 2020, 21:23 - core
Version 2.7.1 is available, it fixes three security vulnerabilities:
Upgrade is recommended for all users.
Saturday, September 23 2017
By Sébastien Helleu on Saturday, September 23 2017, 15:48 - core
Version 1.9.1 is available, it fixes a security vulnerability: a crash can happen in logger plugin when converting date/time specifiers in file mask. Two other bugs are fixed as well in buflist and relay plugins.
Upgrade is recommended for all users.
Sunday, November 18 2012
By Sébastien Helleu on Sunday, November 18 2012, 14:09 - core
Version 0.3.9.2 is available, it fixes a security problem: untrusted command for function hook_process could lead to execution of commands, because of shell expansions.
Upgrade is highly recommended for all users.
Friday, November 9 2012
By Sébastien Helleu on Friday, November 9 2012, 19:55 - core
Version 0.3.9.1 is available, it fixes a security problem (buffer overflow when decoding IRC colors in strings).
Upgrade is recommended for all users.
Sunday, January 31 2010
By Sébastien Helleu on Sunday, January 31 2010, 12:00 - core
Version 0.3.1.1 is available!
This version fixes crashes with SSL connection and purge of old DCC chats. It is recommended to upgrade from 0.3.1 to 0.3.1.1 for all users.