CVE-2013-7449

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:xchat:xchat:-:*:*:*:*:*:*:*
cpe:2.3:a:xchat:xchat_gnome:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:hexchat_project:hexchat:*:*:*:*:*:*:*:*

Information

Published : 2016-04-21 07:59

Updated : 2021-07-20 07:36


NVD link : CVE-2013-7449

Mitre link : CVE-2013-7449


JSON object : View

CWE
CWE-310

Cryptographic Issues

Advertisement

dedicated server usa

Products Affected

canonical

  • ubuntu_linux

xchat

  • xchat
  • xchat_gnome

hexchat_project

  • hexchat