Information on source package weechat

Available versions

ReleaseVersion
bullseye3.0-1+deb11u1
bookworm3.8-1
trixie4.6.3-1
forky4.10.0-1
sid4.10.0-1

Open issues

BugbullseyebookwormtrixieforkysidDescription
TEMP-1142894-D4016AvulnerablevulnerablevulnerablefixedfixedGHSA-rfmh-3r7f-jpx5: Use-after-free in the irc plugin when a batched message disconnects the server
TEMP-1142894-B589E0vulnerablevulnerablevulnerablefixedfixedGHSA-hx59-4hq9-6vmw: relay: use-after-free and double free when a remote relay sends an event with an array as body
TEMP-1142894-2C375FvulnerablevulnerablevulnerablefixedfixedGHSA-q2xg-9ggx-77mr: Stack buffer overflow in irc_message_split_join when building a JOIN with keys
TEMP-1142597-FFA22AvulnerablevulnerablevulnerablefixedfixedGHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm
TEMP-1104554-F3166Cvulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedBuffer overflow in base 32 encoding in evaluated expressions
TEMP-1104554-D6608Cvulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedInteger overflow in conversion of version to an integer
TEMP-1104554-D19F68vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedBuffer overflow in range of chars in evaluated expressions
TEMP-1104554-B16504vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedInteger overflow in base32 decode/encode functions
TEMP-1104554-A4A19Avulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedBuffer overflow in parsing of date/time
TEMP-1104554-71A417vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedInteger overflow with decimal numbers in calculation of expression
TEMP-0000000-F1FB58vulnerablevulnerablevulnerablefixedfixedWSA-2026-5: irc: Buffer overflow when receiving a DCC file
TEMP-0000000-B26F1DvulnerablevulnerablevulnerablefixedfixedWSA-2026-8: relay: Buffer overflow in dump of Relay data
TEMP-0000000-B1CD0AvulnerablevulnerablevulnerablefixedfixedWSA-2026-4: relay: Missing size limit for the received websocket frame, HTTP message and HTTP body
TEMP-0000000-72CE9BvulnerablevulnerablevulnerablefixedfixedWSA-2026-7: xfer: Buffer overflow when receiving a line in a Xfer chat (DCC chat) buffer
TEMP-0000000-40DFCFvulnerablevulnerablevulnerablefixedfixedWSA-2026-11: Logger: Write of logger file outside of configured path
TEMP-0000000-6F5D6BvulnerablevulnerablevulnerablefixedfixedWSA-2026-6: xfer: Write of DCC file received outside of configured download path
TEMP-0000000-5A4286vulnerablevulnerablevulnerablefixedfixedGHSA-wmpc-m6g9-fwj8: relay: Memory leak in API relay, endpoint "handshake"
TEMP-0000000-4D5947vulnerablevulnerablevulnerablefixedfixedWSA-2026-3: irc: Missing size limit for the unterminated IRC message or isupport value (message 005)
CVE-2026-53525vulnerablevulnerablevulnerablefixedfixedWeeChat (Wee Enhanced Environment for Chat) is a free chat client. In ...
CVE-2026-53524vulnerablevulnerablevulnerablefixedfixedWeeChat (Wee Enhanced Environment for Chat) is a free chat client. In ...
CVE-2024-46613vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedWeeChat before 4.4.2 has an integer overflow and resultant buffer over ...

Resolved issues

BugDescription
TEMP-1104554-9D6627Buffer overflow in syntax highlighting of evaluated expressions
CVE-2022-28352WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4. ...
CVE-2021-40516WeeChat before 3.2.1 allows remote attackers to cause a denial of serv ...
CVE-2020-9760An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affe ...
CVE-2020-9759A Vulnerability of LG Electronic web OS TV Emulator could allow an att ...
CVE-2020-8955irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2 ...
CVE-2017-14727logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash v ...
CVE-2017-8073WeeChat before 1.7.1 allows a remote crash by sending a filename via D ...
CVE-2012-5854Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remot ...
CVE-2012-5534The hook_process function in the plugin API for WeeChat 0.3.0 through ...
CVE-2011-1428Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does ...
CVE-2009-0661Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attack ...

Security announcements

DSA / DLADescription
DLA-2770-1weechat - security update
DLA-2157-1weechat - security update
DLA-1111-1weechat - security update
DSA-3836-1weechat - security update
DLA-919-1weechat - security update
DSA-2598-1weechat - several
DSA-1744-1weechat - denial of service

Search for package or bug name: Reporting problems