Bug 2063854 - weechat: SSL verification vulnerability
Summary: weechat: SSL verification vulnerability
Keywords:
Status: CLOSED UPSTREAM
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2063855 2063856
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-03-14 13:57 UTC by Pedro Sampaio
Modified: 2022-03-14 21:01 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2022-03-14 21:01:08 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2022-03-14 13:57:08 UTC
After changing the options weechat.network.gnutls_ca_system or weechat.network.gnutls_ca_user, the TLS verification function is lost.
Consequently, any connection to a server with TLS is made without verifying the certificate, which could lead to a man-in-the-middle attack.
Connection to IRC servers with TLS is affected, as well as any connection a server made by a plugin or a script using the function hook_connect. 

References:

https://weechat.org/doc/security/WSA-2022-1/

Comment 1 Pedro Sampaio 2022-03-14 13:57:29 UTC
Created weechat tracking bugs for this issue:

Affects: epel-all [bug 2063856]
Affects: fedora-all [bug 2063855]

Comment 2 Product Security DevOps Team 2022-03-14 21:01:06 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.