Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21615-1

Опубликовано: 20 авг. 2026
Источник: suse-cvrf

Описание

Security update for weechat

This update for weechat fixes the following issues:

Changes in weechat:

  • Update to 4.10.0:

    Added

    • core: add command /theme (#1338)
    • core: add built-in "light" theme, applied automatically on first start on light-background terminals (#1338)
    • core: add themable flag on configuration options (#1338)
    • core: add options weechat.look.theme and weechat.look.theme_backup (#1338)
    • api: add function theme_register (#1338)
    • fset: add filter t:themable (#1338)
    • relay/api: add resource GET /api/scripts
    • relay: add option relay.network.unix_socket_permissions (#2317)
    • script: add info "script_languages"

    Changed

    • core: improve speed of /upgrade with a lot of buffers and lines (#2338, #2339, #2341)
    • core: improve speed of display of long words in chat area (#2336)
    • core: add condition on connected relay api clients in default value of option weechat.look.hotlist_add_conditions
    • core: add /mute in default command for key Alt+= (toggle filters)
    • api: change type of parameter "pos_option_name" to "const char **" in function config_search_with_string
    • relay/api: add field "last_read_line_id" in GET /api/buffers

    Fixed

    • core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
    • core: fix option weechat.look.color_real_white not applied when color is "white" on 16+ colors terminals (#1742)
    • core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
    • api: fix infinite loop in function string_replace when the search string is empty
    • api: do not free dynamic string on error in function string_dyn_concat
    • irc: fix tag in message with list of names when joining a channel
    • fset: remove error displayed in core buffer when clicking with the mouse below the last option displayed
    • guile, lua, perl, python, ruby, tcl: fix conversion of dates in the API functions
    • irc: fix conversion of dates in received messages

    Security

    • core: fix buffer overflow in display of time in chat area with a custom time format (#2342)
    • core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}" (#2335)
    • core: fix possible buffer overflow in command /color alias (#2330)
    • core: fix possible buffer overflow in list of commands displayed by /help (#2330)
    • irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
    • irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
    • irc: limit size of data received from the server to prevent memory exhaustion
    • irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message (#2322)
    • logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
    • relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
    • relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)
    • relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3, CVE-2026-53524)
    • relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
    • relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
    • relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
    • relay: fix out-of-bounds read in dump of data (#2324)
    • relay/api: fix memory leak in resources "handshake", "input" and "completion" (GHSA-wmpc-m6g9-fwj8)
    • relay: fix read of uncompressed websocket frame (#2331)
    • api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
    • xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory (#2321)
    • xfer: fix out-of-bounds read when receiving empty line in DCC chat (#2323)
    • xfer: fix out-of-bounds write in xfer file transfer resume (#2326)
  • Update to 4.9.5:

    • core: fix buffer overflow in display of time in chat area with a custom time format (#2342)
    • irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
    • irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
    • relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
    • relay: increase max size for decompressed websocket frame
  • Update to 4.9.4:

    Changed

    • core: improve speed of display of long words in chat area (#2336)

    Fixed

    • core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
    • core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}" (#2335)
    • logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
    • relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)
  • Update to 4.9.3:

    • core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
    • core: fix possible buffer overflow in command /color alias (#2330)
    • core: fix possible buffer overflow in list of commands displayed by /help (#2330)
    • api: do not free dynamic string on error in function string_dyn_concat
    • relay/api: fix memory leak in resources "handshake", "input" and "completion" (GHSA-wmpc-m6g9-fwj8)
    • relay: fix read of uncompressed websocket frame (#2331)
    • xfer: fix out-of-bounds write in xfer file transfer resume (#2326)
  • Update to 4.9.2:

    • api: fix infinite loop in function string_replace when the search string is empty
    • irc: limit size of data received from the server to prevent memory exhaustion
    • irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message (#2322)
    • relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
    • relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
    • relay: fix out-of-bounds read in dump of data (#2324)
    • xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory (#2321)
    • xfer: fix out-of-bounds read when receiving empty line in DCC chat (#2323)
  • Update to 4.9.1:

    • core: fix option weechat.look.color_real_white not applied when color is "white" on 16+ colors terminals (#1742)
    • irc: fix tag in message with list of names when joining a channel
    • relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3)
    • relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc)
    • api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc)
  • Update to 4.9.0:

    Added

    • typing: add option typing.look.item_text (#2305)

    Fixed

    • core: fix crash with /eval when the current buffer is closed in a command
    • core: fix buffer size in function util_parse_time, causing buffer overflow error in unit tests
    • irc: fix display of CTCP query sent multiple times to the same user when capability echo-message is enabled (#2309)
    • irc: fix unit of server option anti_flood from seconds to milliseconds in output of /server listfull
    • irc: fix creation of irc.msgbuffer option without a server name
    • irc: ignore self join if the channel is already joined (#2291)
    • relay/api: fix memory leaks in resources "ping" and "sync"
    • relay/api: fix memory leak in receive of message from remote WeeChat
  • Update to 4.8.2:

    • irc: ignore self join if the channel is already joined (#2291)
    • relay/api: fix memory leaks in resources "ping" and "sync"
    • relay/api: fix memory leak in receive of message from remote WeeChat
  • Update to 4.8.1:

    • core: fix buffer size in function util_parse_time, causing buffer overflow error in unit tests
    • irc: fix creation of irc.msgbuffer option without a server name
  • Update to 4.8.0:

    Removed

    • irc: remove temporary servers and option irc.look.temporary_servers

    Changed

    • api: add support of date like ISO 8601 but with spaces and lower t and z in function util_parse_time (#886)
    • irc: request and perform SASL authentication when the server advertises SASL support with message "CAP NEW" (#2277)
    • irc: send SASL username with mechanism EXTERNAL (#2270)
    • logger: change default time format to %@%F %T.%fZ (UTC) (#886)
    • logger: use function util_parse_time to parse date/time in log files (#886)
    • relay/api: return an error 400 (Bad Request) when URL parameters "colors", "nicks", "lines" and "lines_free" have an invalid value
    • relay/api: return an error 401 (Unauthorized) when header "x-weechat-totp" has an invalid value
    • xfer: add buffer local variable "server" in DCC CHAT buffers
    • core, irc, relay: add tag "tls" in gnutls messages
    • irc: add tags "irc_cap" and "log3" in client capability request and SASL not supported messages
    • build: require Curl ≥ 7.68.0 (#2268)
    • build: require GnuTLS ≥ 3.6.3 (#2268)
    • build: require libgcrypt ≥ 1.8.0 (#2268)
    • build: require Enchant v2 (#2268)
    • build: require Lua ≥ 5.3 (#2268)

    Added

    • core: add option weechat.completion.cycle
    • core: add hdata for hooks
    • api: add functions util_parse_int, util_parse_long and util_parse_longlong
    • buflist: add variable ${index_displayed}

    Fixed

    • core: display an error message in case of invalid parameters in commands /bar, /buffer, /cursor, /print and /window
    • api: fix file descriptor leak in hook_url when a timeout occurs or if the hook is removed during the transfer (#2284)
    • api: fix parsing of date/times with timezone offset in function util_parse_time
    • irc: fix warning on creation of irc.msgbuffer option when the server name contains upper case letters (#2281)
    • irc: display a warning for each unknown or invalid server option in commands /connect and /server
    • irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and MODE (#2286)
    • irc: fix reset of color when multiple modes are set with command /mode
    • relay/api: fix crash when an invalid HTTP request is received from a client
    • relay/api: return HTTP error 404 instead of 400 when the buffer is not found in resources completion and input
    • relay/api: return HTTP error 400 in case of invalid body in resource ping

Список пакетов

openSUSE Leap 16.0
weechat-4.10.0-bp160.1.1
weechat-devel-4.10.0-bp160.1.1
weechat-lang-4.10.0-bp160.1.1
weechat-lua-4.10.0-bp160.1.1
weechat-perl-4.10.0-bp160.1.1
weechat-python-4.10.0-bp160.1.1
weechat-ruby-4.10.0-bp160.1.1
weechat-spell-4.10.0-bp160.1.1
weechat-tcl-4.10.0-bp160.1.1

Описание

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a small compressed WebSocket frame (~100 bytes) that decompresses to gigabytes, exhausting all server memory and crashing the entire WeeChat process. The api protocol enables permessage-deflate and requires authentication before WebSocket upgrade. Version 4.9.1 patches the issue.


Затронутые продукты
openSUSE Leap 16.0:weechat-4.10.0-bp160.1.1
openSUSE Leap 16.0:weechat-devel-4.10.0-bp160.1.1
openSUSE Leap 16.0:weechat-lang-4.10.0-bp160.1.1
openSUSE Leap 16.0:weechat-lua-4.10.0-bp160.1.1

Ссылки

Описание

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.


Затронутые продукты
openSUSE Leap 16.0:weechat-4.10.0-bp160.1.1
openSUSE Leap 16.0:weechat-devel-4.10.0-bp160.1.1
openSUSE Leap 16.0:weechat-lang-4.10.0-bp160.1.1
openSUSE Leap 16.0:weechat-lua-4.10.0-bp160.1.1

Ссылки