CVE-2022-28352

EUVD-2022-32802
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle attackers to spoof a TLS chat server via an arbitrary certificate. NOTE: this only affects situations where weechat.network.gnutls_ca_system or weechat.network.gnutls_ca_user is changed without a WeeChat restart.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
mitreCNA
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AC:L/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:R
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
weechatweechat
3.2 ≤
𝑥
< 3.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
weechat
bookworm
3.8-1
fixed
bullseye
3.0-1+deb11u1
not-affected
buster
not-affected
sid
4.4.2-1
fixed
stretch
not-affected
trixie
4.4.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
weechat
bionic
needs-triage
focal
needs-triage
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
needs-triage