Source: weechat Severity: normal Tags: security X-Debbugs-Cc: Debian Security Team <[email protected]>
Dear Maintainer, weechat 4.9.4 was released a few days ago [1] and claims to fix 2 security vulnerabilites. First vulnerability is likely only exploitable by a malicious IRC server [2]. The other vulnerability is in the relay code, and has been assigned GHSA-68ff-gq39-pqjm [3] and the fix is in [4]. Please update weechat in debian. Thank you. [1] https://weechat.org/news/180/20260719-Version-4.9.4/ [2] https://github.com/weechat/weechat/pull/2340 [3] https://github.com/weechat/weechat/security/advisories/GHSA-68ff-gq39-pqjm [4] https://github.com/weechat/weechat/commit/1a89d796c9cd5d99fcaafd76de55b20540efd4cc

