Описание
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| weechat | fixed | 4.9.3-1 | package |
Примечания
https://github.com/weechat/weechat/security/advisories/GHSA-vhv8-g2r9-cwcc
Fixed by: https://github.com/weechat/weechat/commit/30230498b290fc7e2228e336356b69b5be3a76b0 (v4.9.1)
Fixed by: https://github.com/weechat/weechat/commit/c737373d17070035b77acf21a01f21eabfb0e0fb (v4.9.1)
Fixed by: https://github.com/weechat/weechat/commit/1ca2a0025513812885146f5e5d7fe06978167516 (v4.9.1)
https://weechat.org/doc/weechat/security/WSA-2026-2/
EPSS
Связанные уязвимости
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
EPSS