TEMP-1142597-FFA22A

NameTEMP-1142597-FFA22A
DescriptionGHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1142597

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
weechat (PTS)bullseye3.0-1+deb11u1vulnerable
bookworm3.8-1vulnerable
trixie4.6.3-1vulnerable
forky4.9.0-1vulnerable
sid4.9.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
weechatsource(unstable)4.9.4-11142597

Notes

https://github.com/weechat/weechat/security/advisories/GHSA-68ff-gq39-pqjm
Fixed by: https://github.com/weechat/weechat/commit/1a89d796c9cd5d99fcaafd76de55b20540efd4cc (v4.9.4)
check, GHSA-68ff-gq39-pqjm claims >= 4.3.0 but potentially since v2.9-rc1

Search for package or bug name: Reporting problems