Fedora Account System
Red Hat Associate
Red Hat Customer
After changing the options weechat.network.gnutls_ca_system or weechat.network.gnutls_ca_user, the TLS verification function is lost. Consequently, any connection to a server with TLS is made without verifying the certificate, which could lead to a man-in-the-middle attack. Connection to IRC servers with TLS is affected, as well as any connection a server made by a plugin or a script using the function hook_connect. References: https://weechat.org/doc/security/WSA-2022-1/
Created weechat tracking bugs for this issue: Affects: epel-all [bug 2063856] Affects: fedora-all [bug 2063855]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.